chore(deps): update nuget packages (major) - #402
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
3 times, most recently
from
July 2, 2023 06:22
5e954fd to
6f0710d
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
3 times, most recently
from
July 11, 2023 15:44
4d343f8 to
76a482d
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
2 times, most recently
from
August 1, 2023 11:26
d18c345 to
b5c27c7
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
from
August 8, 2023 14:00
b5c27c7 to
3cf7ea9
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
4 times, most recently
from
August 23, 2023 08:42
8016ce9 to
bdc6adf
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
from
September 12, 2023 14:06
bdc6adf to
2f5e66c
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
from
October 10, 2023 13:24
2f5e66c to
3d1725f
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
from
October 24, 2023 13:07
3d1725f to
2a37552
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
3 times, most recently
from
November 15, 2023 03:51
1f9812f to
be36702
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
3 times, most recently
from
December 2, 2023 12:10
cec871c to
96d276d
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
3 times, most recently
from
December 19, 2023 12:55
02d7aaa to
c6b71ae
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
2 times, most recently
from
January 3, 2024 22:44
671f113 to
dff52f2
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
from
June 9, 2024 22:46
7540e16 to
8f881b6
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
from
June 27, 2024 18:18
8f881b6 to
2d81bc5
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
from
July 6, 2024 20:34
2d81bc5 to
eca7496
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
from
July 22, 2024 10:22
eca7496 to
ae1e1e7
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
from
August 9, 2024 13:47
ae1e1e7 to
f2ceeff
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
2 times, most recently
from
August 23, 2024 13:27
94a059e to
6162ed8
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
2 times, most recently
from
August 31, 2024 10:52
2c1b86b to
addfea7
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
3 times, most recently
from
September 12, 2024 16:17
6404a36 to
4a57a70
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
2 times, most recently
from
October 18, 2024 11:27
5cefa53 to
37e024c
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
2 times, most recently
from
November 6, 2024 04:13
8a50d70 to
05b4888
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
3 times, most recently
from
November 13, 2024 22:22
6d955a9 to
51ddcfb
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
3 times, most recently
from
December 9, 2024 05:27
9b52d00 to
6432897
Compare
renovate
Bot
force-pushed
the
renovate/major-nuget
branch
5 times, most recently
from
December 19, 2024 18:08
151b02e to
c0d22c0
Compare
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Motivation
Automated dependency update by Renovate bot.
Description
This PR contains the following updates:
3.7.500.80→4.0.100.93.7.510.6→4.0.101.63.7.502.39→4.0.100.73.7.504.32→4.0.100.78.1.0→9.0.09.0.0→10.1.02025.2.4→2026.2.08.0.24→10.0.108.0.24→10.0.102.7.2→3.1.02.7.2→3.1.09.0.3→10.0.32.11.0→3.1.38.0.0→10.0.16.1.2→7.0.1Testing
This is an automated dependency update. No functional changes are expected.
Impact
Release Notes
aws/aws-sdk-net (AWSSDK.Core)
v4.0.100v4.0.9v4.0.8v4.0.7v4.0.6Compare Source
v4.0.5Compare Source
v4.0.4v4.0.3Compare Source
v4.0.2v4.0.1v4.0.0JetBrains/JetBrains.Annotations (JetBrains.Annotations)
v2026.2.0Compare Source
dotnet/dotnet (Microsoft.AspNetCore.TestHost)
v10.0.10v10.0.9v10.0.8v10.0.7v10.0.6v10.0.5v10.0.4v10.0.3v10.0.2v10.0.1v9.0.7: .NET 9.0.7You can build .NET 9.0 from the repository by cloning the release tag
v9.0.7and following the build instructions in the main README.md.Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.
Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023
v9.0.6: .NET 9.0.6You can build .NET 9.0 from the repository by cloning the release tag
v9.0.6and following the build instructions in the main README.md.Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.
Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023
v9.0.5: .NET 9.0.5You can build .NET 9.0 from the repository by cloning the release tag
v9.0.5and following the build instructions in the main README.md.Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.
Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023
v9.0.4: .NET 9.0.4You can build .NET 9.0 from the repository by cloning the release tag
v9.0.4and following the build instructions in the main README.md.Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.
Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023
v9.0.3: .NET 9.0.3You can build .NET 9.0 from the repository by cloning the release tag
v9.0.3and following the build instructions in the main README.md.Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.
Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023
v9.0.2: .NET 9.0.2You can build .NET 9.0 from the repository by cloning the release tag
v9.0.2and following the build instructions in the main README.md.Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.
Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023
v9.0.1: .NET 9.0.1You can build .NET 9.0 from the repository by cloning the release tag
v9.0.1and following the build instructions in the main README.md.Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.
Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023
v9.0.0: .NET 9.0.0You can build .NET 9.0 from the repository by cloning the release tag
v9.0.0and following the build instructions in the main README.md.Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.
Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023
nats-io/nats.net (NATS.Client.JetStream)
v3.1.0: NATS .NET v3.1.0Minor release on top of 3.0.1. Adds subscription events with an OnSubscribed callback, enables full-graph NuGet dependency auditing, and adds documentation examples.
The async enumerable returned by SubscribeAsync does not establish the subscription until it is iterated. When the enumerable is handed off to another task, the new OnSubscribed callback signals when it is safe to publish messages the subscription must observe:
OnSubscribed fires once the SUB protocol message has been queued on the subscribing connection, which is enough when publishing on the same connection. If the publisher uses a different connection, add a PingAsync round-trip on the subscribing connection after the callback to be sure the server has processed the subscription:
Thanks
v3.0.1: NATS .NET v3.0.1Patch release on top of 3.0.0. Fixes a JetStream list enumeration cancellation bug and adds opt-in W3C Baggage propagation to the OpenTelemetry integration.
Thanks
v3.0.0: NATS .NET v3.0.0NATS .NET 3.0 is now stable. This release has been in the works since early this year and brings OpenTelemetry tracing and metrics, .NET 10 target, and a number of API and behavior changes refined over the preview series. Thanks to everyone who tried the previews and reported issues along the way. There are no changes since 3.0.0-preview.11.
.NET 10 Target
3.0 targets
netstandard2.0,netstandard2.1,net8.0, andnet10.0.net6.0has been dropped.OpenTelemetry
API and behavior changes
Performance and internals
Tests and docs
Thanks
Thanks to the community for the contributions and issue reports behind this release:
Upgrade notes
Details of the API and behavior changes, with the preview each first shipped in.
Target frameworks (since preview.1)
net6.0is dropped andnet10.0added; the full set isnetstandard2.0,netstandard2.1,net8.0,net10.0. Apps targeting .NET 6 or 7 keep working through thenetstandard2.1build, whose encoding hot paths were optimized in 3.0 (#1072), but .NET 8+ gets the fastest code paths.Request-reply defaults to Direct mode (since preview.9)
NatsOpts.RequestReplyModenow defaults toNatsRequestReplyMode.Direct: replies are correlated through the connection's existing inbox subscription instead of setting up a subscription and channel per request. Semantics are unchanged, includingThrowIfNoResponders. To restore the previous behavior:Subscription channel overflow defaults unified (since preview.9)
All entry points (
NatsConnection,NatsClient, DI builders) now share theNatsOptsdefaults: pending channel capacity 16384 (up from 1024) andBoundedChannelFullMode.DropNewest. PreviouslyNatsClientand the DI builders forcedWait, which can stall the socket read loop and get the client disconnected as a slow consumer. If a subscriber now falls behind by more than 16K messages, the newest messages are dropped and surfaced throughMessageDroppedinstead of blocking. To restore blocking, accepting the slow consumer risk:SkipSubjectValidation is obsolete (since preview.9)
The option still works but produces a compiler warning. Validation costs 0-5% on a publish microbenchmark and prevents silently misrouted messages: a subject containing a space splits into subject and reply-to tokens on the wire with no error.
Serializers can opt into message context (since preview.3)
New opt-in
INatsSerializeWithContext<T>,INatsDeserializeWithContext<T>, andINatsSerializerWithContext<T>interfaces receive aNatsMsgContext(subject, reply-to, headers) during (de)serialization. Existing serializers work unchanged. One side effect:NatsHeadersno longer becomes read-only after publish, so a singleNatsHeadersinstance should not be shared across concurrent publishes.Socket interfaces moved to NATS.Client.Abstractions (since preview.11)
INatsSocketConnectionandINatsTlsUpgradeableSocketConnectionmoved to theNATS.Client.Abstractionspackage so custom transports can implement them without referencing Core. The namespace is unchanged and the types are forwarded, so existing code is source and binary compatible.OpenTelemetry package (metrics since preview.8, package since preview.11)
The new
NATS.Client.OpenTelemetrypackage addsAddNatsClientInstrumentation()extensions for bothTracerProviderBuilderandMeterProviderBuilder, with options for subject filtering and custom span destination names.Explicit drain (since preview.9)
INatsSub<T>.DrainAsync()drains a single subscription without disposing the connection: no new deliveries, in-flight messages fenced with a PING/PONG, channel completed.For JetStream consume loops, the opt-in
DrainOnCancelconsume option delivers buffered messages after cancellation so handlers can still ack; the default keeps the previous stop-immediately behavior.DI package dependencies (since preview.2)
NATS.Extensions.Microsoft.DependencyInjectionnow depends onNATS.Client.Simplifiedinstead of the all-inclusiveNATS.Net, andNATS.Netnow includes the DI package. If you referenced only the DI package and used JetStream, Key-Value, Object Store, or Services through its transitive dependency, add a directNATS.Netreference (or the specific packages you use).Full Changelog: nats-io/nats.net@v2.8.2...v3.0.0
v2.8.2: NATS .NET v2.8.2Patch release on the 2.8 line. Fixes ordered push consumer subscription teardown. Thanks to @haoguanjun for the fix.
What's Changed
Full Changelog: nats-io/nats.net@v2.8.1...v2.8.2
v2.8.1: NATS .NET v2.8.1Patch release on the 2.8 line. Bug fixes across JetStream, KV, subscriptions, and connection logging, plus a small Services helper for handling error responses on the requester side.
What's Changed
New Services Extensions
Detect service errors on responses (#1152)
Services signal failures using
Nats-Service-Error/Nats-Service-Error-Coderesponse headers. The requester side previously had to read those headers by hand. New extensions onNatsMsg<T>(in theNATS.Netnamespace) cover the common patterns:Full Changelog: nats-io/nats.net@v2.8.0...v2.8.1
Download from NuGet at https://www.nuget.org/packages/NATS.Net/2.8.1
v2.8.0: NATS .NET v2.8.0Happy to announce the NATS .NET 2.8.0 stable release of the 2.8 line. It picks up the NATS Server v2.14 client surface (consumer reset,
$JS.FC.*flow-control replies,Consumerfield on stream source/mirror,AllowBatchPublishon stream config), ships two breaking changes that landed in the preview cycle, and fixes in-flight message loss on consumer/connection dispose behind an opt-in drain.A big thank you to all NATS contributors and community members who helped make this release possible. <3
NATS Server v2.14 Features
ResetConsumerAsynconINatsJSContextandINatsJSConsumer(ADR-60), to reset a pinned consumer's state (#1126).$JS.FC.*flow-control replies are parsed by the JS metadata layer, for streams that publish with thejs_ack_fc_v2flag (#1127).Consumerfield onStreamSourceand stream mirror config, for pre-created mirror/source consumers (#1128).AllowBatchPublishonStreamConfig(JSONallow_batched), required by streams that opt into fast-ingest batch publishing per ADR-50 (#1120). The fast-ingest publisher itself lives in orbit.net alongside the existing atomic batch publisher.Breaking Changes
Subject Validation On By Default (#1093)
Subjects containing whitespace (space, tab, CR, LF) now throw
NatsException. This closes a class of CRLF injection issues from malformed subjects.Opt out if you rely on legacy subjects that contain whitespace:
NKeyPair Removed From NATS.Client.Core (#1101)
NATS.Client.Core.NKeysandNKeyPairare removed. Signing now goes through theNATS.NKeyspackage, which lets the nkey/Ed25519 code be versioned independently of the client.For typical users this is transparent: keep using
NatsAuthOpts.NKeyFile,CredsFile,Jwt+Seed, orAuthCredCallbackand the client wires up the new signer automatically.Only direct callers of
NATS.Client.Core.NKeyPairneed to switch:Other Notable Changes
NatsConnectionsurfaces server-side errors to client code.auth_requiredadvertisement (#1109), so NKey/credential clients respond to the challenge even when the server doesn't advertiseauth_required.Rangeattribute fix onMaxBytes(#1096).ArrayPoolbuffers are cleared before return to pool (#1097).What's Changed
Since
2.8.0-preview.3:2.8.0-preview.3:$JS.FCsupport to JS metadata parser (#1127) [server 2.14]2.8.0-preview.2:2.8.0-preview.1:Full Changelog: nats-io/nats.net@v2.7.3...v2.8.0
Download from NuGet at https://www.nuget.org/packages/NATS.Net/2.8.0
v2.7.3: NATS .NET v2.7.3Announcing a new version of NATS .NET client library covering various fixes and a security update on one dependency for NETStandard targets (#1089) even though the vulnerable API is not used by our library.
A big thank you to all NATS contributors and community members who helped make this release possible ❤️
Breaking Changes
NakAsync Signature Change (#1081)
The
TimeSpan delayparameter has been removed fromINatsJSMsg<T>.NakAsync(). The delay must now be passed viaAckOpts.NakDelay.Before (v2.7.2):
After (v2.7.3):
Note: because we also have an extension method, recompiling your project is enough.
AckTerminateAsync TermWithReason (#1048, #1081)
AckTerminateAsyncnow supports an optional termination reason. A new overload and a newTerminateReasonproperty onAckOptshave been added toINatsJSMsg<T>. Implementors of this interface must add the new method.Requires NATS Server 2.10.4+.
PinnedClient Validation (#1063)
Calling
NextAsync(),FetchAsync(), orFetchNoWaitAsync()on a consumer withPriorityPolicy.PinnedClientnow throwsNatsJSException. UseConsumeAsync()instead.Consumer Cancellation Handling (#1068)
Consumer methods (
ConsumeAsync,FetchAsync,NextAsync) now callcancellationToken.ThrowIfCancellationRequested()immediately at method entry. Previously cancelled tokens were checked later in the async pipeline.StreamSnapshotRequest ChunkSize Type Change (#1088)
StreamSnapshotRequest.ChunkSizechanged fromlongtoint?with a narrower validation range (1KB–1MB).WindowSize(int?) was added as a new optional property.WindowSizerequires NATS Server 2.12.5+.OpenTelemetry Tag Change (#1078)
The telemetry tag
network.protocol.version(value: protocol version number) has been replaced withnetwork.transport(value:"tcp") to align with OpenTelemetry semantic conventions. Update any dashboards or alerting rules that filter on the old tag name.Default Parameter Values Changed from
defaulttonull(#1081)All optional parameters on
INatsJSMsg<T>methods (AckAsync,NakAsync,AckProgressAsync,AckTerminateAsync,ReplyAsync) changed from= defaultto= null. This is source-compatible but binary-breaking — existing compiled assemblies must be recompiled against v2.7.3.What's Changed
PingCommandcancellation by @mtmk in #1086Full Changelog: nats-io/nats.net@v2.7.2...v2.7.3
CVE Update
Microsoft.Bcl.Memoryis a transitive dependency fornetstandard2.0targets any app pulling inNATS.Client.Coregets it. Even though this library doesn't call the vulnerableBase64Url.DecodeAPI, the consuming application (or another dependency in its graph) might. A CVSSv3 7.5 DoS from a malformed network input is not something you want sitting in your dependency tree. (Microsoft CVE )If you are not upgrading to this new version of NATS .NET AND targeting NETStandard2.0, applications should add an explicit package reference to force the patched version:
You don't need to upgrade NATS.NET itself to get the fix if you need time. NuGet will happily resolve the newer patch version of
Microsoft.Bcl.Memorysince it's within the samemajor.minorrange.Here is a report generated by AI:
Download from NuGet at https://www.nuget.org/packages/NATS.Net/2.7.3
npgsql/npgsql (Npgsql)
v10.0.3Release milestone
Full Changelog: npgsql/npgsql@v10.0.2...v10.0.3
v10.0.2v10.0.2 contains several minor bug fixes.
Milestone issues
Full Changelog: npgsql/npgsql@v10.0.1...v10.0.2
v10.0.1v9.0.4 contains several minor bug fixes.
Milestone issues
Full Changelog: npgsql/npgsql@v10.0.0...v10.0.1
v10.0.0See the release notes.
The full list of changes is available here.
What's Changed