Skip to content

deps: fold the four Dependabot bumps into one commit on top of v2.6.0 - #201

Closed
camarigor wants to merge 1 commit into
ZL154:mainfrom
camarigor:deps/consolidate-dependabot-2026-09
Closed

camarigor wants to merge 1 commit into
ZL154:mainfrom
camarigor:deps/consolidate-dependabot-2026-09

Conversation

@camarigor

Copy link
Copy Markdown
Contributor

Summary

Folds the four open Dependabot PRs into one commit on top of v2.6.0, with the tests lock file regenerated through dotnet restore JellyfinSecurity.sln --force-evaluate rather than copied. Supersedes #184, #185, #186 and #187, which were opened on 2026-08-20 and have not been rebased since.

Dependency From To Where
actions/setup-dotnet v5.4.0 v6.0.0 ci (2 jobs), codeql, dependabot-lockfiles (same SHA as #187)
actions/attest-build-provenance v4.1.1 v4.2.2 release (same SHA as #186)
github/codeql-action init, analyze, upload-sarif v4.37.3 v4.37.9 codeql and scorecard, the three moved together as dependabot.yml requires (same SHA as #185)
NSubstitute 6.1.0 6.2.0 tests csproj (#184)

Type of change

  • Bug fix (non-breaking)
  • New feature (non-breaking)
  • Breaking change (existing behaviour, config, or API changes)
  • Security fix
  • Documentation only
  • CI / build / tests only
  • Refactor (no functional change)

Related issues

Supersedes #184, #185, #186, #187. Follows the same approach as #165 (one commit, every lock file regenerated) and relies on the lock file check from #166.

How was this tested?

  • Added or updated unit tests: existing suite, unchanged
  • Added or updated integration tests
  • Tested manually against a running Jellyfin server (state version)
  • N/A (explain why below)

Nothing here changes the plugin: the four bumps touch workflow pins and the test project only. Verified locally with the .NET 9 SDK CI uses:

  • dotnet restore JellyfinSecurity.sln --force-evaluate, then dotnet restore JellyfinSecurity.sln --locked-mode: passes. Only the tests lock file changed, and only in its NSubstitute entry (requested and resolved 6.1.0 to 6.2.0); the src and fuzz lock files are untouched because NSubstitute is a test-only package.
  • dotnet build JellyfinSecurity.sln -c Release: builds. The four CS8602 warnings in Jellyfin12ShellTests.cs are already on main (the test dereferences the string? from ReadEmbeddedText without a null assert) and are not from this change; I can send a one-line fix separately.
  • dotnet test -c Release: 502 passed, 0 failed.

The workflow pins are exercised by the checks on this PR, since CI, CodeQL and Scorecard run with the bumped actions here.

What changed

  • .github/workflows/ci.yml, codeql.yml, dependabot-lockfiles.yml: actions/setup-dotnet v6.0.0 (ESM migration and dependency bumps upstream; the dotnet-version: "9.0.x" input the workflows use is unchanged).
  • .github/workflows/release.yml: actions/attest-build-provenance v4.2.2 (a wrapper release on top of actions/attest; same inputs).
  • .github/workflows/codeql.yml, scorecard.yml: github/codeql-action v4.37.9 for init, analyze and upload-sarif in the same commit, so the config a newer init writes is read by the same analyze version (the deadlock ci: bump github/codeql-action/analyze from 4.37.3 to 4.37.7 #155 hit).
  • tests/Jellyfin.Plugin.TwoFactorAuth.Tests/Jellyfin.Plugin.TwoFactorAuth.Tests.csproj and its packages.lock.json: NSubstitute 6.2.0 (generic call matching fixes, #989 and #990 upstream; no API removal).

Checklist

  • My code follows the existing style (run dotnet format if unsure)
  • I've added comments only where the why isn't obvious from the code
  • I've updated the README / SECURITY.md / docs if behaviour or config changed (nothing user-facing changed)
  • I've considered backwards compatibility (config migration, file formats, on-disk state)
  • I've checked the security implications (auth bypass, secret handling, input validation): every action stays SHA-pinned, with the SHAs Dependabot resolved
  • CI passes (dotnet build + dotnet test green)

Screenshots / log slices

dotnet restore JellyfinSecurity.sln --locked-mode   -> ok
dotnet test tests/Jellyfin.Plugin.TwoFactorAuth.Tests -c Release
  Passed! - Failed: 0, Passed: 502, Skipped: 0, Total: 502

Additional notes

  • The four Dependabot PRs show mergeable: unknown because they predate the v2.6.0 changes; their SHAs and versions still match what main uses today, which is why this is a faithful supersede rather than a re-resolution.
  • Jellyfin.Controller, Jellyfin.Model, Microsoft.IdentityModel.Tokens and System.IdentityModel.Tokens.Jwt stay as pinned; they are on the Dependabot ignore list on purpose.

actions/setup-dotnet v5.4.0 -> v6.0.0 (ci, codeql, dependabot-lockfiles),
actions/attest-build-provenance v4.1.1 -> v4.2.2 (release),
github/codeql-action init/analyze/upload-sarif v4.37.3 -> v4.37.9 (codeql,
scorecard, moved together as dependabot.yml requires), NSubstitute
6.1.0 -> 6.2.0 (tests). Same SHAs and versions as Dependabot's ZL154#184 to
ZL154#187; the tests lock file comes from dotnet restore --force-evaluate on
the solution with the .NET 9 SDK CI uses, and locked-mode restore passes.
502 tests green.
@camarigor

Copy link
Copy Markdown
Contributor Author

Closing this one in favour of #214, which carries the same four bumps together with the six Dependabot PRs opened on 2026-09-14, on top of the current main (v2.6.1 plus #212) and with the Jellyfin 12 lock file regenerated as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant