Conversation
actions/setup-dotnet v5.4.0 -> v6.0.0 (ci, codeql, dependabot-lockfiles), actions/attest-build-provenance v4.1.1 -> v4.2.2 (release), github/codeql-action init/analyze/upload-sarif v4.37.3 -> v4.37.9 (codeql, scorecard, moved together as dependabot.yml requires), NSubstitute 6.1.0 -> 6.2.0 (tests). Same SHAs and versions as Dependabot's ZL154#184 to ZL154#187; the tests lock file comes from dotnet restore --force-evaluate on the solution with the .NET 9 SDK CI uses, and locked-mode restore passes. 502 tests green.
17 tasks
Contributor
Author
18 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Folds the four open Dependabot PRs into one commit on top of v2.6.0, with the tests lock file regenerated through
dotnet restore JellyfinSecurity.sln --force-evaluaterather than copied. Supersedes #184, #185, #186 and #187, which were opened on 2026-08-20 and have not been rebased since.actions/setup-dotnetactions/attest-build-provenancegithub/codeql-actioninit, analyze, upload-sarifdependabot.ymlrequires (same SHA as #185)NSubstituteType of change
Related issues
Supersedes #184, #185, #186, #187. Follows the same approach as #165 (one commit, every lock file regenerated) and relies on the lock file check from #166.
How was this tested?
Nothing here changes the plugin: the four bumps touch workflow pins and the test project only. Verified locally with the .NET 9 SDK CI uses:
dotnet restore JellyfinSecurity.sln --force-evaluate, thendotnet restore JellyfinSecurity.sln --locked-mode: passes. Only the tests lock file changed, and only in itsNSubstituteentry (requestedandresolved6.1.0 to 6.2.0); the src and fuzz lock files are untouched becauseNSubstituteis a test-only package.dotnet build JellyfinSecurity.sln -c Release: builds. The fourCS8602warnings inJellyfin12ShellTests.csare already onmain(the test dereferences thestring?fromReadEmbeddedTextwithout a null assert) and are not from this change; I can send a one-line fix separately.dotnet test -c Release: 502 passed, 0 failed.The workflow pins are exercised by the checks on this PR, since CI, CodeQL and Scorecard run with the bumped actions here.
What changed
.github/workflows/ci.yml,codeql.yml,dependabot-lockfiles.yml:actions/setup-dotnetv6.0.0 (ESM migration and dependency bumps upstream; thedotnet-version: "9.0.x"input the workflows use is unchanged)..github/workflows/release.yml:actions/attest-build-provenancev4.2.2 (a wrapper release on top ofactions/attest; same inputs)..github/workflows/codeql.yml,scorecard.yml:github/codeql-actionv4.37.9 forinit,analyzeandupload-sarifin the same commit, so the config a newerinitwrites is read by the sameanalyzeversion (the deadlock ci: bump github/codeql-action/analyze from 4.37.3 to 4.37.7 #155 hit).tests/Jellyfin.Plugin.TwoFactorAuth.Tests/Jellyfin.Plugin.TwoFactorAuth.Tests.csprojand itspackages.lock.json:NSubstitute6.2.0 (generic call matching fixes, #989 and #990 upstream; no API removal).Checklist
dotnet formatif unsure)dotnet build+dotnet testgreen)Screenshots / log slices
Additional notes
mergeable: unknownbecause they predate the v2.6.0 changes; their SHAs and versions still match whatmainuses today, which is why this is a faithful supersede rather than a re-resolution.Jellyfin.Controller,Jellyfin.Model,Microsoft.IdentityModel.TokensandSystem.IdentityModel.Tokens.Jwtstay as pinned; they are on the Dependabot ignore list on purpose.