Skip to content

release: bump third-party libraries and toolchain - #117

Merged
tgiachi merged 1 commit into
mainfrom
develop
Sep 1, 2026
Merged

tgiachi merged 1 commit into
mainfrom
develop

Conversation

@tgiachi

@tgiachi tgiachi commented Sep 1, 2026

Copy link
Copy Markdown
Owner

Summary

Applies the available dependency updates (Dependabot group of 27) and cuts a release.

Library updates

  • OpenTelemetry.* 1.17.0 → 1.18.0
  • AWSSDK.SNS / SQS / KMS / SecretsManager 4.0.100.7 → 4.0.100.11
  • StackExchange.Redis 3.1.0 → 3.1.31
  • Elastic.Clients.Elasticsearch 9.5.0 → 9.5.1
  • RabbitMQ.Client 7.2.1 → 7.2.2
  • Microsoft.Extensions.Caching.Memory 10.0.10 → 10.0.11

Build / test / analyzers

  • Microsoft.CodeAnalysis.NetAnalyzers 10.0.302 → 10.0.400
  • Testcontainers.* 4.13.0 → 4.14.0
  • Microsoft.NET.Test.Sdk 18.8.1 → 18.9.0
  • Microsoft.AspNetCore.TestHost 10.0.10 → 10.0.11
  • xunit.runner.visualstudio 3.1.5 → 4.0.0 (major; still runs xunit v2 2.9.3 — verified locally)
  • Microsoft.CodeAnalysis.CSharp / Analyzers 5.6.0 → 5.9.0 (test project only)

Held back

  • Microsoft.CodeAnalysis.CSharp / Analyzers kept at 5.6.0 in SquidStd.Generators: it is a Roslyn source generator and must target a Roslyn ≤ the SDK compiler (10.0.302), otherwise it fails to load and emits nothing (CS0234). Dependabot's bump of that project is a false positive.

Housekeeping

Local Release build is green (0 errors); a sample test class runs under the new xunit runner. CI validates the full suite before merge.

- OpenTelemetry.* 1.17.0 -> 1.18.0
- AWSSDK.SNS/SQS/KeyManagementService/SecretsManager 4.0.100.7 -> 4.0.100.11
- StackExchange.Redis 3.1.0 -> 3.1.31
- Elastic.Clients.Elasticsearch 9.5.0 -> 9.5.1
- RabbitMQ.Client 7.2.1 -> 7.2.2
- Microsoft.Extensions.Caching.Memory 10.0.10 -> 10.0.11
- Microsoft.CodeAnalysis.NetAnalyzers 10.0.302 -> 10.0.400
- Testcontainers.* 4.13.0 -> 4.14.0
- Microsoft.NET.Test.Sdk 18.8.1 -> 18.9.0
- Microsoft.AspNetCore.TestHost 10.0.10 -> 10.0.11
- xunit.runner.visualstudio 3.1.5 -> 4.0.0 (still runs xunit v2 2.9.3, verified)
- Microsoft.CodeAnalysis.CSharp/Analyzers 5.6.0 -> 5.9.0 in the test project only

Held Microsoft.CodeAnalysis.CSharp/Analyzers at 5.6.0 in SquidStd.Generators: a
source generator must target a Roslyn <= the SDK compiler (10.0.302) that loads
it, so 5.9.0 makes it fail to load and emit nothing (CS0234). Dependabot's bump
of that project is a false positive.

Supersedes and closes the stale Dependabot PR #116.
@tgiachi
tgiachi merged commit 7543c34 into main Sep 1, 2026
3 checks passed
tgiachi added a commit that referenced this pull request Sep 1, 2026
The semantic-release step ran unpinned via npx, so it resolved the latest of
each package. conventional-changelog-conventionalcommits@10 now requires
conventional-changelog-writer@9, but @semantic-release/release-notes-generator@14
and commit-analyzer@13 ship writer@8, so release-notes rendering crashed with
"Missing helper". This broke the v0.41.2 release (PR #117 merged to main, tag
never created).

Pin semantic-release@24 and conventional-changelog-conventionalcommits@9 (the
preset major that matches writer@8). Verified with a local `semantic-release
--dry-run` on main: computes 0.41.2 and renders the notes cleanly.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant