Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Jan 19, 2026

Updated CommunityToolkit.Aspire.Hosting.Ollama from 9.8.0-beta.395 to 13.1.1.

Release notes

Sourced from CommunityToolkit.Aspire.Hosting.Ollama's releases.

13.1.1

Small fix release that includes a missing API surface area file.

What's Changed

Full Changelog: CommunityToolkit/Aspire@v13.1.0...v13.1.1

13.1.0

Happy 2026 everyone, and welcome to the first release for 2026!

Big ticket items this release are:

  • Support for Aspire 13.1
  • New integrations for flagd, SFTP, Elasticvue, Flyway, and Stripe CLI (I think that's all 😅)
  • Improvements to the MCP Inspector integration to support Bun
  • RavenDB hosting integration got some improvements
    There is one potentially breaking change in this release with Dapr - we've found some of the tests are failing in CI for reasons we can't figure out, so as a result we're marking the Dapr integrations as preview. Nothing has actually changed in them, but there may be something underlying that has changed, so be aware and if you do find problems - report them!

What's Changed

New Contributors

13.0.0

It's here, we now support Aspire 13! 🎉🎉🎉

There's a pretty huge amount of changes, some of which are breaking, so here's the highlights:

  • Support for Aspire 13
  • Support for .NET 10
  • Rename of Hosting.NodeJS.Extensions to Hosting.JavaScript.Extensions to align with Aspire 13
  • Removal of Vite, Yarn, and pnpm extensions (moved to Aspire)
  • Removal of Python uv and uvcorn extensions (moved to Aspire)
  • OTEL support for GoFeatureFlags and Data API builder
  • Support for running native Ollama (using the Ollama binary) rather than containerised (note - this does not deploy, if you want to deploy you'll need to use the containerised Ollama)

What's Changed

New Contributors

9.9.0

Pretty big set of changes for the 9.9.0 release of the Community Toolkit with new integrations for flagd and Keycloak with PostgreSQL.

We've also deprecated the EventStore integration and replaced it with a new KurrentDB one, to reflect the new naming on the project.

Full changelog below.

What's Changed

New Contributors

Full Changelog: CommunityToolkit/Aspire@v9.8.0...v9.9.0

9.8.0

Time for another big release of the Aspire Community Toolkit with the main features being:

  • Support for Aspire 9.5
  • Open Telemetry Collector hosting integration
  • Apache Solr hosting integration

We also have a change to the package versioning for the SQLite EF Core integration, it's now marked as a pre-release package as it brings support for OTEL via their NuGet package, but their package is in beta, so we have to publish a pre-release version of our package too.

What's Changed

New Contributors

Commits viewable in compare view.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

….1.1

---
updated-dependencies:
- dependency-name: CommunityToolkit.Aspire.Hosting.Ollama
  dependency-version: 13.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Jan 19, 2026
@socket-security
Copy link

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
License policy violation: nuget microsoft.bcl.asyncinterfaces

License: GPL-2.0-or-later WITH Classpath-exception-2.0 - the applicable license policy does not allow this license (4). the applicable license policy does not allow this license exception (THIRD-PARTY-NOTICES.TXT)

From: src/eShop.AppHost/packages.lock.jsonnuget/microsoft.bcl.asyncinterfaces@8.0.0

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.bcl.asyncinterfaces@8.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: nuget microsoft.extensions.filesystemglobbing under NIST-Software

License: NIST-Software - the applicable license policy does not allow this license (4) (THIRD-PARTY-NOTICES.TXT)

From: src/eShop.AppHost/packages.lock.jsonnuget/microsoft.extensions.filesystemglobbing@10.0.1

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore nuget/microsoft.extensions.filesystemglobbing@10.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants