Skip to content

Conversation

@renovate
Copy link

@renovate renovate bot commented Jan 8, 2026

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Adoption Passing Confidence Type Update Pending
Microsoft.AspNetCore.Authentication.JwtBearer (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.AspNetCore.Authentication.OpenIdConnect (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.AspNetCore.Components.QuickGrid (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.AspNetCore.Components.Web (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.AspNetCore.Identity.EntityFrameworkCore (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.AspNetCore.Identity.UI (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.AspNetCore.Mvc.Testing (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.AspNetCore.OpenApi (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.AspNetCore.TestHost (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.EntityFrameworkCore.Tools (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.Extensions.ApiDescription.Server (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.Extensions.Configuration.Abstractions (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.Extensions.Http.Resilience (source) 10.0.010.2.0 age adoption passing confidence nuget minor
Microsoft.Extensions.Identity.Stores (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.Extensions.Logging.Abstractions (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.Extensions.Options (source) 10.0.010.0.2 age adoption passing confidence nuget patch
Microsoft.Extensions.ServiceDiscovery (source) 10.0.010.2.0 age adoption passing confidence nuget minor
Microsoft.Extensions.ServiceDiscovery.Yarp (source) 10.0.010.2.0 age adoption passing confidence nuget minor
Microsoft.Maui.Controls 9.0.409.0.120 age adoption passing confidence nuget patch
Microsoft.Maui.Controls.Compatibility 9.0.409.0.120 age adoption passing confidence nuget patch
Microsoft.Maui.Controls.Maps 9.0.409.0.120 age adoption passing confidence nuget patch
Microsoft.VisualStudio.Web.CodeGeneration.Design 8.0.0-rc.1.23461.38.0.22 age adoption passing confidence nuget patch 8.0.23
dotnet-sdk 10.0.10110.0.102 age adoption passing confidence dotnet-sdk patch

Release Notes

dotnet/dotnet (Microsoft.AspNetCore.Authentication.JwtBearer)

v10.0.2

v10.0.1

dotnet/extensions (Microsoft.Extensions.Http.Resilience)

v10.2.0

What's Changed

New Contributors

Full Changelog: dotnet/extensions@v10.1...v10.2.0

dotnet/maui (Microsoft.Maui.Controls)

v9.0.120: SR 12

Compare Source

What's Changed

.NET 9 SR12 introduces significant improvements across all platforms with focus on quality, performance, and developer experience. This release includes 104 commits with various improvements, bug fixes, and enhancements.

.NET MAUI Product Fixes
Android
BlazorWebView
Button
Collectionview
Controls Entry
Controls Flyout
Controls Searchbar
Controls Titleview
Data Binding
Drawing
Entry
Gestures
Infrastructure
Layout
Navigation
Other
Refreshview
Shapes
Shell
TabbedPage
Theming
WebView
Windows
Xaml
🧪 Testing (29)
🏠 Housekeeping (15)
**Full Changelog**: https://github.com/dotnet/maui/compare/9.0.111...9.0.120

[v9.0.111](https://redirect.github.com/dotnet/maui/release


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM ( * 0-3 * * * ) in timezone Europe/Madrid, Automerge - Between 12:00 AM and 03:59 AM ( * 0-3 * * * ) in timezone Europe/Madrid.

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the renovate label Jan 8, 2026
@renovate renovate bot requested a review from Pinguladora January 8, 2026 23:48
@renovate
Copy link
Author

renovate bot commented Jan 8, 2026

⚠️ Artifact update problem

Renovate failed to update artifacts related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: src/Basket.API/packages.lock.json, src/eShop.AppHost/packages.lock.json, tests/Basket.UnitTests/packages.lock.json, src/Catalog.API/packages.lock.json, tests/Catalog.FunctionalTests/packages.lock.json, src/ClientApp/packages.lock.json, tests/ClientApp.UnitTests/packages.lock.json, src/EventBus/packages.lock.json, src/EventBusRabbitMQ/packages.lock.json, src/OrderProcessor/packages.lock.json, src/Ordering.API/packages.lock.json, tests/Ordering.FunctionalTests/packages.lock.json, tests/Ordering.UnitTests/packages.lock.json, src/PaymentProcessor/packages.lock.json, src/WebApp/packages.lock.json, src/Webhooks.API/packages.lock.json, src/IntegrationEventLogEF/packages.lock.json, src/Ordering.Infrastructure/packages.lock.json, src/HybridApp/packages.lock.json, src/Identity.API/packages.lock.json, src/Ordering.Domain/packages.lock.json, src/WebAppComponents/packages.lock.json, src/WebhookClient/packages.lock.json, src/eShop.ServiceDefaults/packages.lock.json
  Determining projects to restore...
/opt/containerbase/tools/dotnet/sdk/10.0.102/Sdks/Microsoft.NET.Sdk/targets/Microsoft.NET.Sdk.ImportWorkloads.targets(38,5): error NETSDK1147: To build this project, the following workloads must be installed: maui-tizen [/tmp/renovate/repos/github/Pinguteca/eShop/tests/ClientApp.UnitTests/ClientApp.UnitTests.csproj]
/opt/containerbase/tools/dotnet/sdk/10.0.102/Sdks/Microsoft.NET.Sdk/targets/Microsoft.NET.Sdk.ImportWorkloads.targets(38,5): error NETSDK1147: To install these workloads, run the following command: dotnet workload restore [/tmp/renovate/repos/github/Pinguteca/eShop/tests/ClientApp.UnitTests/ClientApp.UnitTests.csproj]

File name: src/Basket.API/packages.lock.json, src/eShop.AppHost/packages.lock.json, tests/Basket.UnitTests/packages.lock.json, src/Catalog.API/packages.lock.json, tests/Catalog.FunctionalTests/packages.lock.json, src/ClientApp/packages.lock.json, tests/ClientApp.UnitTests/packages.lock.json, src/EventBus/packages.lock.json, src/EventBusRabbitMQ/packages.lock.json, src/OrderProcessor/packages.lock.json, src/Ordering.API/packages.lock.json, tests/Ordering.FunctionalTests/packages.lock.json, tests/Ordering.UnitTests/packages.lock.json, src/PaymentProcessor/packages.lock.json, src/WebApp/packages.lock.json, src/Webhooks.API/packages.lock.json, src/IntegrationEventLogEF/packages.lock.json, src/Ordering.Infrastructure/packages.lock.json, src/HybridApp/packages.lock.json, src/Identity.API/packages.lock.json, src/Ordering.Domain/packages.lock.json, src/WebAppComponents/packages.lock.json, src/WebhookClient/packages.lock.json, src/eShop.ServiceDefaults/packages.lock.json
  Determining projects to restore...
/opt/containerbase/tools/dotnet/sdk/10.0.102/Sdks/Microsoft.NET.Sdk/targets/Microsoft.NET.Sdk.ImportWorkloads.targets(38,5): error NETSDK1147: To build this project, the following workloads must be installed: maui-tizen [/tmp/renovate/repos/github/Pinguteca/eShop/tests/ClientApp.UnitTests/ClientApp.UnitTests.csproj]
/opt/containerbase/tools/dotnet/sdk/10.0.102/Sdks/Microsoft.NET.Sdk/targets/Microsoft.NET.Sdk.ImportWorkloads.targets(38,5): error NETSDK1147: To install these workloads, run the following command: dotnet workload restore [/tmp/renovate/repos/github/Pinguteca/eShop/tests/ClientApp.UnitTests/ClientApp.UnitTests.csproj]

File name: tests/ClientApp.UnitTests/packages.lock.json
  Determining projects to restore...
/opt/containerbase/tools/dotnet/sdk/10.0.102/Sdks/Microsoft.NET.Sdk/targets/Microsoft.NET.Sdk.ImportWorkloads.targets(38,5): error NETSDK1147: To build this project, the following workloads must be installed: maui-tizen [/tmp/renovate/repos/github/Pinguteca/eShop/tests/ClientApp.UnitTests/ClientApp.UnitTests.csproj]
/opt/containerbase/tools/dotnet/sdk/10.0.102/Sdks/Microsoft.NET.Sdk/targets/Microsoft.NET.Sdk.ImportWorkloads.targets(38,5): error NETSDK1147: To install these workloads, run the following command: dotnet workload restore [/tmp/renovate/repos/github/Pinguteca/eShop/tests/ClientApp.UnitTests/ClientApp.UnitTests.csproj]

@renovate renovate bot force-pushed the renovate/dotnet-monorepo branch 5 times, most recently from f165842 to 9e984da Compare January 11, 2026 21:16
@renovate renovate bot force-pushed the renovate/dotnet-monorepo branch from 9e984da to a36e299 Compare January 27, 2026 01:28
@socket-security
Copy link

socket-security bot commented Jan 27, 2026

@socket-security
Copy link

socket-security bot commented Jan 27, 2026

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
License policy violation: nuget microsoft.extensions.caching.abstractions

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.extensions.identity.stores@10.0.2nuget/microsoft.extensions.caching.abstractions@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.caching.abstractions@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.configuration.abstractions

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.extensions.identity.stores@10.0.2nuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/asp.versioning.http.client@8.1.0nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.configuration.abstractions@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.configuration.abstractions@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.configuration.abstractions

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

From: tests/ClientApp.UnitTests/ClientApp.UnitTests.csprojnuget/microsoft.maui.controls@9.0.120nuget/microsoft.maui.controls.compatibility@9.0.120nuget/microsoft.extensions.configuration.abstractions@9.0.9

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.configuration.abstractions@9.0.9. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.configuration.binder

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.extensions.identity.stores@10.0.2nuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/asp.versioning.http.client@8.1.0nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.configuration.binder@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.configuration.binder@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.configuration.commandline

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.configuration.commandline@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.configuration.commandline@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.configuration.environmentvariables

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.configuration.environmentvariables@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.configuration.environmentvariables@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.configuration.fileextensions

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.configuration.fileextensions@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.configuration.fileextensions@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.configuration.json

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.configuration.json@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.configuration.json@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.configuration.usersecrets

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.configuration.usersecrets@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.configuration.usersecrets@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.configuration

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.extensions.identity.stores@10.0.2nuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/asp.versioning.http.client@8.1.0nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.configuration@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.configuration@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.configuration

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

From: tests/ClientApp.UnitTests/ClientApp.UnitTests.csprojnuget/microsoft.maui.controls@9.0.120nuget/microsoft.maui.controls.compatibility@9.0.120nuget/microsoft.extensions.configuration@9.0.9

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.configuration@9.0.9. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.dependencyinjection.abstractions

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.extensions.identity.stores@10.0.2nuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/microsoft.extensions.logging@8.0.0nuget/asp.versioning.http.client@8.1.0nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.dependencyinjection.abstractions@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.dependencyinjection.abstractions@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.dependencyinjection.abstractions

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

From: tests/ClientApp.UnitTests/ClientApp.UnitTests.csprojnuget/microsoft.maui.controls@9.0.120nuget/microsoft.maui.controls.compatibility@9.0.120nuget/microsoft.extensions.dependencyinjection.abstractions@9.0.9

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.dependencyinjection.abstractions@9.0.9. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.dependencyinjection

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.extensions.identity.stores@10.0.2nuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/microsoft.extensions.logging@8.0.0nuget/asp.versioning.http.client@8.1.0nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.dependencyinjection@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.dependencyinjection@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.dependencyinjection

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

From: tests/ClientApp.UnitTests/ClientApp.UnitTests.csprojnuget/microsoft.maui.controls@9.0.120nuget/microsoft.maui.controls.compatibility@9.0.120nuget/microsoft.extensions.dependencyinjection@9.0.9

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.dependencyinjection@9.0.9. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.dependencymodel

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/microsoft.extensions.dependencymodel@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.dependencymodel@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.diagnostics.abstractions

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.extensions.identity.stores@10.0.2nuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/asp.versioning.http.client@8.1.0nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.diagnostics.abstractions@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.diagnostics.abstractions@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.diagnostics

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.extensions.identity.stores@10.0.2nuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/asp.versioning.http.client@8.1.0nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.diagnostics@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.diagnostics@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.fileproviders.abstractions

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.fileproviders.abstractions@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.fileproviders.abstractions@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.fileproviders.physical

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.fileproviders.physical@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.fileproviders.physical@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.filesystemglobbing

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.filesystemglobbing@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.filesystemglobbing@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.hosting.abstractions

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: tests/Basket.UnitTests/Basket.UnitTests.csprojnuget/microsoft.aspnetcore.mvc.testing@10.0.2nuget/aspire.hosting.postgresql@13.0.1nuget/microsoft.extensions.hosting.abstractions@10.0.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.hosting.abstractions@10.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

See 39 more rows in the dashboard

View full report

@renovate renovate bot force-pushed the renovate/dotnet-monorepo branch from a36e299 to a4c44d8 Compare January 27, 2026 22:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant