Skip to content

deps: Bump FluentAssertions and xunit.runner.visualstudio - #570

Closed
dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/nuget/test-dependencies-97c0f8bbd5
Closed

dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/nuget/test-dependencies-97c0f8bbd5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Updated FluentAssertions from 6.12.2 to 8.10.0.

Release notes

Sourced from FluentAssertions's releases.

8.10.0

What's Changed

Improvements

Documentation

Others

Full Changelog: fluentassertions/fluentassertions@8.9.0...8.10.0

8.9.0

[!WARNING]
For projects targeting .NET 9, you need at least .NET SDK 9.0.200 as earlier versions will trigger compile errors because of invalid overload resolution. See #​3225

What's Changed

New features

Improvements

Fixes

Documentation

Others

8.8.0

What's Changed

New features

Improvements

Documentation

Others

Full Changelog: fluentassertions/fluentassertions@8.7.1...8.8.0

8.7.1

What's Changed

Others

Full Changelog: fluentassertions/fluentassertions@8.7.0...8.7.1

8.7.0

What's Changed

New features

Others

Full Changelog: fluentassertions/fluentassertions@8.6.0...8.7.0

8.6.0

What's Changed

Improvements

Others

New Contributors

Full Changelog: fluentassertions/fluentassertions@8.5.0...8.6.0

8.5.0

What's Changed

New features

Fixes

Others

Full Changelog: fluentassertions/fluentassertions@8.4.0...8.5.0

8.4.0

What's Changed

Improvements

Others

New Contributors

Full Changelog: fluentassertions/fluentassertions@8.3.0...8.4.0

8.3.0

What's Changed

Improvements

Others

Full Changelog: fluentassertions/fluentassertions@8.2.0...8.3.0

8.2.0

What's Changed

Improvements

Fixes

Others

Full Changelog: fluentassertions/fluentassertions@8.1.1...8.2.0

8.1.1

What's Changed

Fixes

Full Changelog: fluentassertions/fluentassertions@8.1.0...8.1.1

8.1.0

What's Changed

Improvements

Fixes

Documentation

Others

New Contributors

Full Changelog: fluentassertions/fluentassertions@8.0.1...8.1.0

8.0.1

What's Changed

Improvements

Others

Full Changelog: fluentassertions/fluentassertions@8.0.0...8.0.1

8.0.0

What's Changed

License change

Breaking Changes

New features

Improvements

8.0.0-rc.2

What's Changed

Fixes

Others

Full Changelog: fluentassertions/fluentassertions@8.0.0-rc.1...8.0.0-rc.2

8.0.0-rc.1

What's Changed

Breaking Changes

Fixes

Documentation

Others

8.0.0-alpha.1

What's Changed

Others

Full Changelog: fluentassertions/fluentassertions@7.0.0-alpha.6...8.0.0-alpha.1

7.2.2

What's Changed

Fixes

Building

Full Changelog: fluentassertions/fluentassertions@7.2.1...7.2.2

7.2.1

What's Changed

Fixes

Full Changelog: fluentassertions/fluentassertions@7.2.0...7.2.1

7.2.0

What's Changed

Improvements

Fixes

Others

Full Changelog: fluentassertions/fluentassertions@7.1.0...7.2.0

7.1.0

What's Changed

Improvements

Others

Full Changelog: fluentassertions/fluentassertions@7.0.0...7.1.0

7.0.0

What's Changed

Breaking Changes

Fixes

Documentation

Others

New Contributors

Full Changelog: fluentassertions/fluentassertions@6.12.2...7.0.0

Commits viewable in compare view.

Updated xunit.runner.visualstudio from 2.8.2 to 4.0.0.

Release notes

Sourced from xunit.runner.visualstudio's releases.

4.0.0

Release notes: https://xunit.net/releases/visualstudio/4.0.0

4.0.0-pre.5

Release notes: https://xunit.net/releases/visualstudio/4.0.0-pre.5

4.0.0-pre.4

Release notes: https://xunit.net/releases/visualstudio/4.0.0-pre.4

4.0.0-pre.3

Release notes: https://xunit.net/releases/visualstudio/4.0.0-pre.3

3.1.5

Release notes: https://xunit.net/releases/visualstudio/3.1.5

Commits viewable in compare view.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 17, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: nuget. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@socket-security

socket-security Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednuget/​fluentassertions@​6.12.2 ⏵ 8.10.097 +51009010080 -19
Updatednuget/​xunit.runner.visualstudio@​2.8.2 ⏵ 4.0.096 +410090100100

View full report

@github-actions

github-actions Bot commented Aug 17, 2026 •

Copy link
Copy Markdown
Contributor

Test Results

0 tests   0 ✅  0s ⏱️
0 suites  0 💤
0 files    0 ❌

Results for commit d69434d.

♻️ This comment has been updated with latest results.

@dependabot
dependabot Bot changed the base branch from master to staging August 17, 2026 13:00
@dependabot
dependabot Bot force-pushed the dependabot/nuget/test-dependencies-97c0f8bbd5 branch from 7083140 to 612e11f Compare August 17, 2026 13:00
@dependabot dependabot Bot changed the title deps: Bump the test-dependencies group with 7 updates deps: Bump FluentAssertions and 6 others Aug 17, 2026
@leinss

leinss commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

Superseded in part by #584, which takes the safe subset of this group: Microsoft.AspNetCore.Mvc.Testing, Microsoft.NET.Test.Sdk, NUnit, NUnit.Analyzers and xunit.

Two entries here are deliberately not being taken:

  • FluentAssertions 6.12.2 -> 8.10.0 — v8 moved off Apache-2.0 to a paid commercial licence, free only for non-commercial use. Merging it introduces a per-developer paid dependency in the test suite. It is used in 18 files, so replacing it is a migration to decide on its own.
  • xunit.runner.visualstudio 2.8.2 -> 4.0.0 — major runner bump while the xunit core stays on 2.x. That class of mismatch usually fails by discovering no tests rather than by erroring, so it needs a change that checks discovered counts explicitly.

Two more are already satisfied on staging and would be no-ops: Autofac is pinned at 9.3.1 to match the runtime image, and Nethermind.ReferenceAssemblies is already 1.39.3.

Leaving this open so the grouped PR recalculates after #584 lands.

Bumps FluentAssertions from 6.12.2 to 8.10.0
Bumps xunit.runner.visualstudio from 2.8.2 to 4.0.0

---
updated-dependencies:
- dependency-name: FluentAssertions
  dependency-version: 8.10.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: test-dependencies
- dependency-name: Microsoft.AspNetCore.Mvc.Testing
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-dependencies
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: test-dependencies
- dependency-name: NUnit
  dependency-version: 4.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-dependencies
- dependency-name: NUnit.Analyzers
  dependency-version: 4.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: test-dependencies
- dependency-name: xunit
  dependency-version: 2.9.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-dependencies
- dependency-name: xunit.runner.visualstudio
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: test-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title deps: Bump FluentAssertions and 6 others deps: Bump FluentAssertions and xunit.runner.visualstudio Aug 24, 2026
@dependabot
dependabot Bot force-pushed the dependabot/nuget/test-dependencies-97c0f8bbd5 branch from 612e11f to d69434d Compare August 24, 2026 02:59
@leinss

leinss commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Closing: FluentAssertions 8.x cannot be adopted here.

Two independent blockers, both verified from the package metadata rather than the release notes:

  • Licence. 6.12.2 and the whole 7.x line publish <license type="expression">Apache-2.0</license> in their nuspec. 8.0.0 replaced that with a licence file, sets requireLicenseAcceptance, and its description states that commercial use requires a paid Xceed licence.
  • Build. v7 renamed BeGreaterOrEqualTo and BeLessOrEqualTo. Three tests call them, so build-and-test fails with CS1061 at BackgroundServiceTests.cs:52, CacheContainerTests.cs:181 and PathfinderGraphControllerTests.cs:190.

#598 adds a bounded ignore at >=8.0.0 so this stops being reopened weekly. 7.x stays proposable: it is Apache-2.0, and moving to it means fixing those three call sites.

@leinss leinss closed this Sep 14, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/nuget/test-dependencies-97c0f8bbd5 branch September 14, 2026 10:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant