deps(nuget): Bump the dotnet-minor-patch group with 5 updates - #1527
deps(nuget): Bump the dotnet-minor-patch group with 5 updates#1527dependabot[bot] wants to merge 2 commits into
Conversation
Bumps FsCheck from 3.3.3 to 3.3.4 Bumps FsCheck.Xunit from 3.3.3 to 3.3.4 Bumps Microsoft.IdentityModel.Tokens from 8.19.2 to 8.21.0 Bumps Sentry.AspNetCore from 6.7.0 to 6.8.0 Bumps System.IdentityModel.Tokens.Jwt from 8.19.2 to 8.21.0 --- updated-dependencies: - dependency-name: FsCheck dependency-version: 3.3.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dotnet-minor-patch - dependency-name: FsCheck.Xunit dependency-version: 3.3.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dotnet-minor-patch - dependency-name: Microsoft.IdentityModel.Tokens dependency-version: 8.21.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dotnet-minor-patch - dependency-name: Sentry.AspNetCore dependency-version: 6.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dotnet-minor-patch - dependency-name: System.IdentityModel.Tokens.Jwt dependency-version: 8.21.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dotnet-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
Fresh adversarial review — current head FindingsNo code, dependency-compatibility, DCO, or release/security finding. The central-package diff keeps the IdentityModel pair aligned at 8.21.0 and the FsCheck pair aligned at 3.3.4; hosted backend/API/unit, dependency-security, DCO, and CodeQL checks are green/neutral as expected. I read all existing PR-conversation comments, reviews, and review threads: all were empty. Residual merge gates
Recommendation: merge-ready only after those two current-base/governance gates are satisfied. |
|
Superseded by #1545, which carries the same five-line package update on current Keep this PR open until #1545 lands; then close it as superseded if Dependabot does not do so automatically. |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Updated FsCheck from 3.3.3 to 3.3.4.
Release notes
Sourced from FsCheck's releases.
3.3.4
Fixed a bug in C# record type generation.
Commits viewable in compare view.
Updated FsCheck.Xunit from 3.3.3 to 3.3.4.
Updated Microsoft.IdentityModel.Tokens from 8.19.2 to 8.21.0.
Release notes
Sourced from Microsoft.IdentityModel.Tokens's releases.
8.20.0
Performance Improvements
Bug Fixes
Full Changelog: AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@8.19.2...8.20.0
Commits viewable in compare view.
Updated Sentry.AspNetCore from 6.7.0 to 6.8.0.
Release notes
Sourced from Sentry.AspNetCore's releases.
6.8.0
Features ✨
Logs
log4netintegration by @Flash0ver in #5172NLogintegration by @Flash0ver in #5176Other
AddToTransactionsonSentryAttachment#5182 by @jamescrosswell in #5182SentrySdk.RecordTransactionto record already-completed transactions and spans (e.g. replayed through a proxy) #5333 by @jamescrosswell in #5333Environmentset on theScopenow gets synchronized to the native layers (sentry-cocoaandsentry-native) by @bitsandfoxes in #5365Fixes 🐛
SentrySpanProcessorno longer leaks spans whose Activity never ends (e.g. aborted requests); the Activity is now held via aWeakReferenceso orphaned spans are pruned once it is garbage-collected. by @Ermabo in #5393Dependencies ⬆️
Deps
Other
Commits viewable in compare view.
Updated System.IdentityModel.Tokens.Jwt from 8.19.2 to 8.21.0.
Release notes
Sourced from System.IdentityModel.Tokens.Jwt's releases.
8.20.0
Performance Improvements
Bug Fixes
Full Changelog: AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@8.19.2...8.20.0
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions