Skip to content

chore(deps): Bump DocumentFormat.OpenXml and 7 others - #192

Merged
elson-vinicius-lopes merged 2 commits into
developfrom
dependabot/nuget/ai/XslSynth.Core.Tests/develop/runtime-minor-patch-f26aacb8c8
Aug 26, 2026
Merged

chore(deps): Bump DocumentFormat.OpenXml and 7 others#192
elson-vinicius-lopes merged 2 commits into
developfrom
dependabot/nuget/ai/XslSynth.Core.Tests/develop/runtime-minor-patch-f26aacb8c8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 26, 2026

Copy link
Copy Markdown
Contributor

Updated DocumentFormat.OpenXml from 3.3.0 to 3.5.1.

Release notes

Sourced from DocumentFormat.OpenXml's releases.

3.5.1

Added

  • Added DocumentFormat.OpenXml.Office2016.Drawing.ChartDrawing.Offset class
  • Added Version attribute to DocumentFormat.OpenXml.Office2016.Drawing.ChartDrawing.ChartSpace
  • Added FeatureList attribute to DocumentFormat.OpenXml.Office2016.Drawing.ChartDrawing.ChartSpace
  • Added FalbackImg attribute to DocumentFormat.OpenXml.Office2016.Drawing.ChartDrawing.ChartSpace
  • Added DocumentFormat.OpenXml.Office2016.Drawing.ChartDrawing.ExtensionDropMode enum

3.4.1

Added

  • Added MediaDataPartType.Mp4 to support MP4 video media parts in presentations and documents (#​1866)
  • Updated bundled Open XML schemas to the Q3 2025 Office release, enabling newer document and presentation features (#​1963)

Changed

  • Reduced JIT and AOT size and improved document load performance by removing the generic builder pattern from element metadata creation (#​1842, #​1843)
  • Optimized FromChunkedBase64String to significantly reduce allocations and improve throughput when decoding chunked base64 content (≈2.4× faster, ≈70% less memory) (#​1868)

Fixed

  • Switched to XmlDOMTextWriter instead of XmlWriter.Create to correctly handle serialization of certain XML content (#​1869, #​1961)
  • Added a clear error when attempting to open encrypted documents that the SDK cannot process (#​1635, #​1969)
  • Improved exception messages when required package parts are missing by including the name of the missing part (#​1971, #​1974)

Documentation

  • Clarified the README SDK description and simplified the note on 3.0.0 breaking changes (#​1858)
  • Documented that disposing a package with AutoSave set to false does not persist changes (#​1873)
  • Removed the PowerPoint modern comments sample, which now lives on learn.microsoft.com (#​1861)

Thanks to the following for their contributions:

@​QuocDatHoang
@​Varorbc

Commits viewable in compare view.

Updated Microsoft.Extensions.Hosting from 10.0.0 to 10.0.11.

Release notes

Sourced from Microsoft.Extensions.Hosting's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Http from 10.0.0 to 10.0.11.

Release notes

Sourced from Microsoft.Extensions.Http's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.NET.Test.Sdk from 18.8.1 to 18.9.0.

Release notes

Sourced from Microsoft.NET.Test.Sdk's releases.

18.9.0

What's Changed

New Contributors

Full Changelog: microsoft/vstest@v18.8.0...v18.9.0

Commits viewable in compare view.

Updated PdfPig from 0.1.15 to 0.1.16.

Release notes

Sourced from PdfPig's releases.

0.1.16

What's Changed

New Contributors

Full Changelog: UglyToad/PdfPig@v0.1.15...v0.1.16

Commits viewable in compare view.

Updated Serilog from 4.2.0 to 4.4.0.

Release notes

Sourced from Serilog's releases.

4.4.0

What's Changed

New Contributors

Full Changelog: serilog/serilog@v4.3.1...v4.4.0

4.3.1

What's Changed

New Contributors

Full Changelog: serilog/serilog@v4.3.0...v4.3.1

4.3.0

What's Changed

  • #​2149 - LogEvent.AddPropertyIfAbsent(ILogEventPropertyFactory, ...) overload that helps avoid allocations (@​vanni-giachin)
  • #​2158 - use HTTPS in all README.md images and links (@​TimHess)
  • #​2163 - LogContext.Push() overloads accepting IEnumerable<ILogEventEnricher> and ReadOnlySpan<ILogEventEnricher> (@​SimonCropp)
  • #​2175, #​2178, #​2179 - fix AOT compatibility (@​agocke)

New Contributors

Full Changelog: serilog/serilog@v4.2.0...v4.3.0

Commits viewable in compare view.

Pinned Serilog at 4.4.0.

Release notes

Sourced from Serilog's releases.

4.4.0

What's Changed

New Contributors

Full Changelog: serilog/serilog@v4.3.1...v4.4.0

4.3.1

What's Changed

New Contributors

Full Changelog: serilog/serilog@v4.3.0...v4.3.1

Commits viewable in compare view.

Updated Serilog.Sinks.Console from 6.0.0 to 6.1.1.

Release notes

Sourced from Serilog.Sinks.Console's releases.

6.1.1

What's Changed

Full Changelog: serilog/serilog-sinks-console@v6.1.0...v6.1.1

6.1.0

  • #​165 - support for {UtcTimestamp} in output templates (@​ManuelRin)
  • #​172, #​173 - switch build to Serilog org standard (@​nblumhardt)

Commits viewable in compare view.

Updated StackExchange.Redis from 3.1.13 to 3.1.31.

Release notes

Sourced from StackExchange.Redis's releases.

No release notes found for this version range.

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps DocumentFormat.OpenXml from 3.3.0 to 3.5.1
Bumps Microsoft.Extensions.Hosting from 10.0.0 to 10.0.11
Bumps Microsoft.Extensions.Http from 10.0.0 to 10.0.11
Bumps Microsoft.NET.Test.Sdk from 18.8.1 to 18.9.0
Bumps PdfPig from 0.1.15 to 0.1.16
Bumps Serilog to 4.4.0
Bumps Serilog.Sinks.Console from 6.0.0 to 6.1.1
Bumps StackExchange.Redis from 3.1.13 to 3.1.31

---
updated-dependencies:
- dependency-name: DocumentFormat.OpenXml
  dependency-version: 3.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: runtime-minor-patch
- dependency-name: Microsoft.Extensions.Hosting
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: runtime-minor-patch
- dependency-name: Microsoft.Extensions.Http
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: runtime-minor-patch
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: runtime-minor-patch
- dependency-name: PdfPig
  dependency-version: 0.1.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: runtime-minor-patch
- dependency-name: Serilog
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: runtime-minor-patch
- dependency-name: Serilog
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: runtime-minor-patch
- dependency-name: Serilog
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: runtime-minor-patch
- dependency-name: Serilog.Sinks.Console
  dependency-version: 6.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: runtime-minor-patch
- dependency-name: Serilog.Sinks.Console
  dependency-version: 6.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: runtime-minor-patch
- dependency-name: StackExchange.Redis
  dependency-version: 3.1.31
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: runtime-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Aug 26, 2026
@github-actions

github-actions Bot commented Aug 26, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
nuget/Serilog 4.4.0 🟢 5.9
Details
CheckScoreReason
Code-Review🟢 7Found 17/24 approved changesets -- score normalized to 7
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained🟢 85 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 8
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
nuget/Serilog.Sinks.File 7.0.0 UnknownUnknown
nuget/ModelContextProtocol 2.2.0 UnknownUnknown
nuget/Serilog.Extensions.Hosting 10.0.0 UnknownUnknown
nuget/Serilog.Sinks.File 7.0.0 UnknownUnknown

Scanned Files

  • LayoutParserApi.csproj
  • ai/XslSynth/XslSynth.csproj
  • mcp/LayoutParserMcp/LayoutParserMcp.csproj

@elson-vinicius-lopes
elson-vinicius-lopes merged commit 8dfb8df into develop Aug 26, 2026
3 checks passed
@elson-vinicius-lopes
elson-vinicius-lopes deleted the dependabot/nuget/ai/XslSynth.Core.Tests/develop/runtime-minor-patch-f26aacb8c8 branch August 26, 2026 13:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant