Repository navigation
Chore: Bump the minor-and-patch group with 11 updates - #165
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps Akka.Cluster.Hosting from 1.5.71 to 1.5.72 Bumps Akka.Hosting from 1.5.71 to 1.5.72 Bumps AngleSharp from 1.8.2 to 1.8.3 Bumps Aspire.Hosting from 13.5.4 to 13.6.0 Bumps MessagePack from 3.1.10 to 3.1.11 Bumps Microsoft.Identity.Web from 4.15.0 to 4.16.0 Bumps Microsoft.Identity.Web.DownstreamApi from 4.15.0 to 4.16.0 Bumps MudBlazor.Extensions from 9.10.0 to 9.11.0 Bumps Scalar.AspNetCore from 2.17.10 to 2.17.13 Bumps SIPSorcery from 10.0.16 to 10.0.17 Bumps SIPSorceryMedia.FFmpeg from 10.0.16 to 10.0.17 --- updated-dependencies: - dependency-name: Akka.Cluster.Hosting dependency-version: 1.5.72 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: Akka.Cluster.Hosting dependency-version: 1.5.72 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: Akka.Hosting dependency-version: 1.5.72 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: AngleSharp dependency-version: 1.8.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: Aspire.Hosting dependency-version: 13.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: MessagePack dependency-version: 3.1.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: Microsoft.Identity.Web dependency-version: 4.16.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: Microsoft.Identity.Web.DownstreamApi dependency-version: 4.16.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: MudBlazor.Extensions dependency-version: 9.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: Scalar.AspNetCore dependency-version: 2.17.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: Scalar.AspNetCore dependency-version: 2.17.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: SIPSorcery dependency-version: 10.0.17 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: SIPSorceryMedia.FFmpeg dependency-version: 10.0.17 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated Akka.Cluster.Hosting from 1.5.71 to 1.5.72.
Release notes
Sourced from Akka.Cluster.Hosting's releases.
1.5.72
1.5.72 October 3rd, 2026
Akka.NET v1.5.72 backports a non-blocking Cluster extension startup, test-infrastructure hardening, a Cluster.Sharding hand-over fix, and a batch of de-flaked specs from
dev.Starting with this release, Akka.Hosting ships from this repository. The
Akka.Hosting,Akka.Remote.Hosting,Akka.Cluster.Hosting,Akka.Persistence.Hosting,Akka.Hosting.TestKit, andAkka.Hosting.TestKit.Xunit2packages are now built, tested, and published alongside every Akka.NET release at the same version number.Akka.Hosting
src/contrib/hostingand share the Akka.NET version and release cadence. No package IDs, namespaces, or public APIs changed; bumpAkka.Hosting.*to the same version asAkka.*. Hosting-only hotfix versions (such as1.5.60.1) no longer exist: a Hosting fix ships in the next Akka.NET patch release. The documentation moved to getakka.net/articles/hosting. The akkadotnet/Akka.Hosting repository will be archived and keeps the full commit history and release notes for versions up to 1.5.71; the import was taken from commitcefe3c4c.Akka,Akka.DependencyInjectionand allAkka.Hosting.*packages now requireMicrosoft.Extensions.*10.0.0 or later (previously 6.0 for the core packages and 9.0 for Akka.Hosting). The 10.0 packages still shipnetstandard2.0assets, so applications on .NET Framework 4.8, .NET 6 and .NET 8 keep working; NuGet will lift the transitiveMicrosoft.Extensions.*references in those applications to 10.0.x. Akka.Hosting'sOpenTelemetrydependency moves to 1.15.3 or later, which clears GHSA-g94r-2vxg-569j.Akka.TestKit / Akka.TestKit.Xunit
Akka.TestKit.Xunit.TestKitnow implementsInitializeAsync/DisposeAsyncdirectly instead of relying on a derived class's own no-op overrides. Breaking change: a derived spec that already declares its ownInitializeAsync/DisposeAsyncmust mark themoverrideand call the base method, or the build fails withCS0114.Dispose(bool)no longer terminates theActorSystemby itself; the publicDispose()/DisposeAsync()entry points do, after calling the base chain.TestKitBase.ShutdownAsyncoverloads shut anActorSystemdown without blocking a thread pool worker.ConductorBindExceptionandConductorPortSentineltypes, and a 20-minute backstop that kills a node process that never exits on its own.Akka.Streams
ServerBinding.Unbind()used to always wait out the subscription timeout even when no connection was pending. It now completes right away in that case, and still correctly waits when a connection was accepted but never subscribed to.Akka.Cluster.Sharding
updating-state-timeout(5 seconds by default), matching whatreference.confalways documented, instead ofwaiting-for-state-timeout(2 seconds). Migration: if you raisedwaiting-for-state-timeoutto give a slow remember-entities store more time, move that value toupdating-state-timeoutinstead - it no longer affects the write path.ShardRegionthat isn't leaving the cluster, which used to leave that region permanently unusable for the life of the process.Akka.DistributedData
Replicatorstarted after a member had already begun leaving no longer silently drops that member's writes and gossip.Akka.Cluster
akka.cluster.prune-gossip-tombstones-after). The wire change is rolling-upgrade compatible: older nodes ignore the added protobuf field and upgraded nodes treat its absence as an empty tombstone set. Protection becomes fully effective after every node is upgraded; removals that occur while old nodes remain in the cluster are not guaranteed to retain their tombstones.Clusterconstructor no longer blocks on a 20 second ask, andakka.actor.creation-timeoutis no longer consulted by Akka.Cluster at all (Akka.Cluster.Sharding still uses it to bound its own start-up asks). This removes the "Failed to startup Cluster" failure mode, which could shut down a healthy node whenever every thread the startup needed was parked - a small fork-join or other dedicated dispatcher pool, or a stock pool starved under load. Behavior note:Cluster.Get()now returns before core initialization completes, and the cluster's internal actor tree (/system/cluster/core,/system/cluster/core/daemon,/system/cluster/heartbeatReceiver) is created afterCluster.Get()returns rather than before it. All public cluster APIs are message-based, so typical code is unaffected; code that usedCluster.Get()as a "core is started" synchronization point, or that resolves one of those internal paths right after obtaining the extension, should awaitJoinAsync/RegisterOnMemberUpor a cluster event instead.Subscribe,Join,Leave,Down, ...) now route through/system/clusterfor the entire lifetime of the extension - two extra local mailbox hops on this low-traffic control plane - instead of switching to a direct core-daemon reference once startup resolves one, so back-to-back commands from one caller stay in order for good, not just during startup. A lostLeaveno longer wedges every laterLeaveAsync()for the life of the process. Behavior note: callingLeave()/LeaveAsync()again after the extension has already shut down now produces a dead-letteredClusterUserAction.Leave- worth knowing about for dead-letter alerting orEventFilter.DeadLetterassertions.Testing
ResolveOneagainst/system/cluster/core/daemon/downingProviderraced the async cluster-extension init #8359 introduces above; replaced with a dilated retrying resolve, a dynamic port, and an asyncTaskCompletionSourcemember-up signal.3 contributors since release 1.5.71
To see the full set of changes in Akka.NET v1.5.72, click here.
Changes:
... (truncated)
Commits viewable in compare view.
Updated Akka.Hosting from 1.5.71 to 1.5.72.
Release notes
Sourced from Akka.Hosting's releases.
1.5.72
1.5.72 October 3rd, 2026
Akka.NET v1.5.72 backports a non-blocking Cluster extension startup, test-infrastructure hardening, a Cluster.Sharding hand-over fix, and a batch of de-flaked specs from
dev.Starting with this release, Akka.Hosting ships from this repository. The
Akka.Hosting,Akka.Remote.Hosting,Akka.Cluster.Hosting,Akka.Persistence.Hosting,Akka.Hosting.TestKit, andAkka.Hosting.TestKit.Xunit2packages are now built, tested, and published alongside every Akka.NET release at the same version number.Akka.Hosting
src/contrib/hostingand share the Akka.NET version and release cadence. No package IDs, namespaces, or public APIs changed; bumpAkka.Hosting.*to the same version asAkka.*. Hosting-only hotfix versions (such as1.5.60.1) no longer exist: a Hosting fix ships in the next Akka.NET patch release. The documentation moved to getakka.net/articles/hosting. The akkadotnet/Akka.Hosting repository will be archived and keeps the full commit history and release notes for versions up to 1.5.71; the import was taken from commitcefe3c4c.Akka,Akka.DependencyInjectionand allAkka.Hosting.*packages now requireMicrosoft.Extensions.*10.0.0 or later (previously 6.0 for the core packages and 9.0 for Akka.Hosting). The 10.0 packages still shipnetstandard2.0assets, so applications on .NET Framework 4.8, .NET 6 and .NET 8 keep working; NuGet will lift the transitiveMicrosoft.Extensions.*references in those applications to 10.0.x. Akka.Hosting'sOpenTelemetrydependency moves to 1.15.3 or later, which clears GHSA-g94r-2vxg-569j.Akka.TestKit / Akka.TestKit.Xunit
Akka.TestKit.Xunit.TestKitnow implementsInitializeAsync/DisposeAsyncdirectly instead of relying on a derived class's own no-op overrides. Breaking change: a derived spec that already declares its ownInitializeAsync/DisposeAsyncmust mark themoverrideand call the base method, or the build fails withCS0114.Dispose(bool)no longer terminates theActorSystemby itself; the publicDispose()/DisposeAsync()entry points do, after calling the base chain.TestKitBase.ShutdownAsyncoverloads shut anActorSystemdown without blocking a thread pool worker.ConductorBindExceptionandConductorPortSentineltypes, and a 20-minute backstop that kills a node process that never exits on its own.Akka.Streams
ServerBinding.Unbind()used to always wait out the subscription timeout even when no connection was pending. It now completes right away in that case, and still correctly waits when a connection was accepted but never subscribed to.Akka.Cluster.Sharding
updating-state-timeout(5 seconds by default), matching whatreference.confalways documented, instead ofwaiting-for-state-timeout(2 seconds). Migration: if you raisedwaiting-for-state-timeoutto give a slow remember-entities store more time, move that value toupdating-state-timeoutinstead - it no longer affects the write path.ShardRegionthat isn't leaving the cluster, which used to leave that region permanently unusable for the life of the process.Akka.DistributedData
Replicatorstarted after a member had already begun leaving no longer silently drops that member's writes and gossip.Akka.Cluster
akka.cluster.prune-gossip-tombstones-after). The wire change is rolling-upgrade compatible: older nodes ignore the added protobuf field and upgraded nodes treat its absence as an empty tombstone set. Protection becomes fully effective after every node is upgraded; removals that occur while old nodes remain in the cluster are not guaranteed to retain their tombstones.Clusterconstructor no longer blocks on a 20 second ask, andakka.actor.creation-timeoutis no longer consulted by Akka.Cluster at all (Akka.Cluster.Sharding still uses it to bound its own start-up asks). This removes the "Failed to startup Cluster" failure mode, which could shut down a healthy node whenever every thread the startup needed was parked - a small fork-join or other dedicated dispatcher pool, or a stock pool starved under load. Behavior note:Cluster.Get()now returns before core initialization completes, and the cluster's internal actor tree (/system/cluster/core,/system/cluster/core/daemon,/system/cluster/heartbeatReceiver) is created afterCluster.Get()returns rather than before it. All public cluster APIs are message-based, so typical code is unaffected; code that usedCluster.Get()as a "core is started" synchronization point, or that resolves one of those internal paths right after obtaining the extension, should awaitJoinAsync/RegisterOnMemberUpor a cluster event instead.Subscribe,Join,Leave,Down, ...) now route through/system/clusterfor the entire lifetime of the extension - two extra local mailbox hops on this low-traffic control plane - instead of switching to a direct core-daemon reference once startup resolves one, so back-to-back commands from one caller stay in order for good, not just during startup. A lostLeaveno longer wedges every laterLeaveAsync()for the life of the process. Behavior note: callingLeave()/LeaveAsync()again after the extension has already shut down now produces a dead-letteredClusterUserAction.Leave- worth knowing about for dead-letter alerting orEventFilter.DeadLetterassertions.Testing
ResolveOneagainst/system/cluster/core/daemon/downingProviderraced the async cluster-extension init #8359 introduces above; replaced with a dilated retrying resolve, a dynamic port, and an asyncTaskCompletionSourcemember-up signal.3 contributors since release 1.5.71
To see the full set of changes in Akka.NET v1.5.72, click here.
Changes:
... (truncated)
Commits viewable in compare view.
Updated AngleSharp from 1.8.2 to 1.8.3.
Release notes
Sourced from AngleSharp's releases.
1.8.3
Released on Wednesday, September 30 2026
What's Changed
<base>elements not following frozen document base URL and tree-order mutation rules (#1355, #1362)Unloadinghandlers subscribing tounloadinginstead ofbeforeunload(#1354) @PrzemyslawKlysOnResetevent to inform script hosts of native listener removals (#1356) @PrzemyslawKlysNew Contributors
Full Changelog: AngleSharp/AngleSharp@v1.8.2...v1.8.3
Commits viewable in compare view.
Updated Aspire.Hosting from 13.5.4 to 13.6.0.
Release notes
Sourced from Aspire.Hosting's releases.
13.6.0
Aspire 13.6.0
Aspire 13.6 brings persistent application history, a refreshed and more interactive dashboard, first-party Java and Rust hosting, and new Azure deployment options. Coordinated .NET builds, portable volume paths, sharper CLI workflows, and more capable editor tooling make it easier to build, debug, and deploy applications across languages.
Highlights
WithRepl()commands open bundled clients for PostgreSQL, MySQL, MongoDB, SQL Server, Redis, and Valkey, whileaspire terminal psandaspire terminal tape playsupport discovery and repeatable terminal interactions.Aspire.Hosting.JavaandAspire.Hosting.Rustpackages bring Maven, Gradle, Spring Boot, Quarkus, and Cargo applications into the app model, with generated container builds and VS Code debugging. These integrations build on work that originated in the Aspire Community Toolkit.Aspire.Hosting.Dotnetintegration coordinates compatible projects into shared restore and build groups and supports .NET SDK container publishing. Portable volume-path environment variables work across local execution and deployment, while TypeScript AppHosts gain standardappsettings.jsonconfiguration and Deno runtime support.aspire runandaspire start, update repository-local CLI manifests withaspire update, create file-based C# AppHosts withaspire init --language csharp --file-based, and export TypeScript API data withaspire sdk export. Terminal commands no longer need a feature flag, Linux certificate trust includes Firefox NSS databases, andaspire stop --force --volumesadds explicit cleanup of Aspire-owned volumes.ASPIRE_HOME, Kubernetes preserves inherited hostnames and embedded parameter values, and AKS gains persistent-volume provisioning and more reliable cleanup.Notable changes include automatic TLS for local MongoDB servers when a certificate is available, the Linux-based vNext Cosmos DB emulator becoming the default, new Azure Front Door origin names that can require cleanup of existing origins, portable connection-string environment-variable aliases on stricter deployment targets, and experimental terminal types moving from
Aspire.Hosting.TerminalstoAspire.Hosting.ApplicationModel.See the full list and migration guidance in the Aspire 13.6 breaking changes.
📖 Learn more
For complete details, examples, migration guidance, and everything new in this release, read What's new in Aspire 13.6.
Thank you to all the community contributors who helped make Aspire 13.6 possible! 💜
Full Changelog: v13.5.4...v13.6.0
Full commit: 56f3e9c0d216c0c7069dabb49dd0464e4827744f
Commits viewable in compare view.
Updated MessagePack from 3.1.10 to 3.1.11.
Release notes
Sourced from MessagePack's releases.
3.1.11
Security fix
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.1.10...v3.1.11
Commits viewable in compare view.
Updated Microsoft.Identity.Web from 4.15.0 to 4.16.0.
Release notes
Sourced from Microsoft.Identity.Web's releases.
4.16.0
What's Changed
Full Changelog: AzureAD/microsoft-identity-web@4.15.0...4.16.0
Commits viewable in compare view.
Updated Microsoft.Identity.Web.DownstreamApi from 4.15.0 to 4.16.0.
Release notes
Sourced from Microsoft.Identity.Web.DownstreamApi's releases.
4.16.0
What's Changed
Full Changelog: AzureAD/microsoft-identity-web@4.15.0...4.16.0
Commits viewable in compare view.
Updated MudBlazor.Extensions from 9.10.0 to 9.11.0.
Release notes
Sourced from MudBlazor.Extensions's releases.
9.11.0
MudBlazor.Extensions 9.11.0
Get MudBlazor.Extensions 9.11.0 on NuGet
New file viewers
Image viewer
MudExImageViewer.Fixes
MudExFileDisplayinstance is reused for another file.Demo and tests
Commits viewable in compare view.
Updated Scalar.AspNetCore from 2.17.10 to 2.17.13.
Release notes
Sourced from Scalar.AspNetCore's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated SIPSorcery from 10.0.16 to 10.0.17.
Release notes
Sourced from SIPSorcery's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated SIPSorceryMedia.FFmpeg from 10.0.16 to 10.0.17.
Release notes
Sourced from SIPSorceryMedia.FFmpeg's releases.
No release notes found for this version range.
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions