Skip to content

chore(deps): Keep risky majors out of the NuGet group, move Testcontainers together - #132

Merged
mpaulosky merged 1 commit into
mainfrom
chore/dependabot-majors-testcontainers
Sep 29, 2026
Merged

mpaulosky merged 1 commit into
mainfrom
chore/dependabot-majors-testcontainers

Conversation

@mpaulosky

Copy link
Copy Markdown
Owner

Why

The recreated Dependabot group PR #128 fails, and would be risky even once it builds:

Package #128 Problem
Testcontainers 4.7.0 → 4.15.0 Testcontainers.MongoDb/.Redis left on 4.7.0. Build fails (UntilPortIsAvailable removed), and after that all 54 Mongo integration tests fail with MissingMethodException.
Radzen.Blazor 7.3.2 → 11.4.1 Four majors. 16 bUnit tests fail (Radzen.createDataGrid JS call). Component and theme changes need a manual UI check.
MessagePack 2.5.302 → 3.1.9 Pinned only to force a patched transitive version. Aspire's StreamJsonRpc 2.25.29 is built against 2.5.302, so a forced 3.x risks runtime failures in the AppHost that Dependabot PRs don't test.

What

.github/dependabot.yml (nuget):

  • ignore semver-major updates of Radzen.Blazor and MessagePack. Minor and patch updates still come through.
  • New testcontainers group (Testcontainers*) ahead of all-nuget, so the core and its modules always move together.

Testcontainers aligned now: Testcontainers, .MongoDb and .Redis go to 4.15.0. IssueTrackerTestFactory switches to UntilInternalTcpPortIsAvailable, the 4.15 name for the same wait.

Validation

  • dotnet build -c Release: 0 errors.
  • Every test project except AppHost.Tests (418 of 418 pass), including PlugIns integration (54, against a real Mongo container).
  • yamllint clean on dependabot.yml.

After merge

@dependabot recreate on #128. It should come back without the Radzen and MessagePack majors or Testcontainers. The Radzen 11 upgrade gets its own PR.

🤖 Generated with Claude Code

…iners together

The all-nuget group (#128) broke the build in three ways:

- It raised Testcontainers to 4.15.0 but left Testcontainers.MongoDb and
  .Redis on 4.7.0. The 4.7 modules can't run on the 4.15 core
  (MissingMethodException in every Mongo integration test).
- It jumped Radzen.Blazor four majors (7.3.2 -> 11.4.1).
- It jumped MessagePack to 3.x, although it is pinned only to force a
  patched transitive version and Aspire's StreamJsonRpc is built on 2.5.x.

Dependabot now skips major versions of Radzen.Blazor and MessagePack, and
puts every Testcontainers package in its own group so they always move
together. Testcontainers and its modules move to 4.15.0 here, with the
wait strategy renamed to UntilInternalTcpPortIsAvailable (the old
UntilPortIsAvailable is gone in 4.15).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings September 29, 2026 00:03

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The dependency alignment, API migration, and Dependabot rules are internally consistent and valid.

Review effort: Balanced
Findings: None

What changed in this PR

Aligns Testcontainers dependencies and prevents risky major upgrades from entering grouped Dependabot PRs.

Changes:

  • Aligns all Testcontainers packages at 4.15.0.
  • Migrates to the renamed internal-port wait API.
  • Separates Testcontainers updates and excludes risky majors.
File Description
.github/​dependabot.yml Adds exclusions and a Testcontainers group.
Directory.Packages.props Aligns Testcontainers package versions.
tests/​IssueTracker.PlugIns.Tests.Integration/​IssueTrackerTestFactory.cs Updates the wait-strategy API call.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

Copy link
Copy Markdown
Contributor

Test Results Summary

412 tests  ±0   412 ✅ ±0   15s ⏱️ +3s
  8 suites ±0     0 💤 ±0 
  8 files   ±0     0 ❌ ±0 

Results for commit 83b47f9. ± Comparison against base commit acd1bef.

@codecov

codecov Bot commented Sep 29, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.59%. Comparing base (acd1bef) to head (83b47f9).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #132   +/-   ##
=======================================
  Coverage   85.59%   85.59%           
=======================================
  Files          77       77           
  Lines        1562     1562           
  Branches      143      143           
=======================================
  Hits         1337     1337           
  Misses        180      180           
  Partials       45       45           

@mpaulosky
mpaulosky merged commit 71e2e7f into main Sep 29, 2026
24 checks passed
@mpaulosky
mpaulosky deleted the chore/dependabot-majors-testcontainers branch September 29, 2026 00:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants