Skip to content

Bump the nuget-minor-and-patch group with 8 updates - #9

Merged
Niewski merged 1 commit into
mainfrom
dependabot/nuget/src/BallBank.Api/nuget-minor-and-patch-b12f02139a
Sep 24, 2026
Merged

Niewski merged 1 commit into
mainfrom
dependabot/nuget/src/BallBank.Api/nuget-minor-and-patch-b12f02139a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Contributor

Updated Aspire.Hosting.JavaScript from 13.5.3 to 13.5.4.

Release notes

Sourced from Aspire.Hosting.JavaScript's releases.

13.5.4

What's New in Aspire 13.5.4

Patch release for Aspire 13.5 that fixes Kafka health-check resource leaks, DevTunnel errors with automatically selected regions, misleading Azure emulator dashboard entries, and unintended changes to generated starter apps, plus Homebrew compatibility and Radius API diagnostic updates.

🐛 Fixes

  • 📨 Kafka health checks leaked producers and polling threads — Each AppHost health-check execution created a new Kafka producer without disposing it, accumulating background threads over time. Health checks now reuse a producer per Kafka resource and dispose it with the AppHost, while keeping multiple Kafka resources independently configured. Fixes #​20091. (#​20094, backport of #​20092, @​davidfowl)

  • 🌐 DevTunnels could fail when the region was selected automatically — Tunnel setup and health checks now use the cluster-qualified tunnel ID returned by the DevTunnel CLI for port operations and access queries. This fixes failures when a bare tunnel ID cannot be resolved for those operations. Regression introduced in 13.3. Fixes #​18790. (#​19853, backport of #​19230, @​Vladipz)

  • ☁️ Emulator-only AppHosts showed an unused Azure environment — The dashboard now hides the azure-environment resource when no Azure resources require cloud provisioning, instead of leaving it visible in Not started. It remains visible for apps that combine local emulators with resources requiring Azure provisioning. No AppHost changes are needed. Fixes #​19617. (#​19998, backport of #​19843, @​eerhardt)

  • 🧩 Starter app generation could alter unrelated JavaScript values — Dynamic port replacement could also replace matching numeric literals in bundled JavaScript, including Bootstrap timing values. Port substitutions are now restricted to localhost: URLs, preserving the original library files while still configuring the requested ports. Fixes #​20030. (#​20110, backport of #​20031, @​bart-vmware, @​JamesNK)

  • 🍎 Updated the Aspire Homebrew cask for Homebrew 6.x — Replaced deprecated cask URL and post-install syntax with the supported equivalents, resolving compatibility issues with current Homebrew while preserving install-channel metadata. (#​20119, backport of #​19965, @​askpt, @​joperezr)

  • 🧪 Radius cloud-provider callback interfaces now carry the experimental diagnostic — IAwsRadiusProviderBuilder and IAzureRadiusProviderBuilder are now marked with ASPIRERADIUS003, matching the existing WithAwsProvider and WithAzureProvider methods. Code referencing these interfaces directly must now acknowledge the same experimental API diagnostic. (#​19874, @​sebastienros)


Full Changelog: v13.5.3...v13.5.4

Full commit: 9c1b401dd67746739044f68959cbf4d3d7af93a6

Commits viewable in compare view.

Updated Aspire.Hosting.PostgreSQL from 13.5.3 to 13.5.4.

Release notes

Sourced from Aspire.Hosting.PostgreSQL's releases.

13.5.4

What's New in Aspire 13.5.4

Patch release for Aspire 13.5 that fixes Kafka health-check resource leaks, DevTunnel errors with automatically selected regions, misleading Azure emulator dashboard entries, and unintended changes to generated starter apps, plus Homebrew compatibility and Radius API diagnostic updates.

🐛 Fixes

  • 📨 Kafka health checks leaked producers and polling threads — Each AppHost health-check execution created a new Kafka producer without disposing it, accumulating background threads over time. Health checks now reuse a producer per Kafka resource and dispose it with the AppHost, while keeping multiple Kafka resources independently configured. Fixes #​20091. (#​20094, backport of #​20092, @​davidfowl)

  • 🌐 DevTunnels could fail when the region was selected automatically — Tunnel setup and health checks now use the cluster-qualified tunnel ID returned by the DevTunnel CLI for port operations and access queries. This fixes failures when a bare tunnel ID cannot be resolved for those operations. Regression introduced in 13.3. Fixes #​18790. (#​19853, backport of #​19230, @​Vladipz)

  • ☁️ Emulator-only AppHosts showed an unused Azure environment — The dashboard now hides the azure-environment resource when no Azure resources require cloud provisioning, instead of leaving it visible in Not started. It remains visible for apps that combine local emulators with resources requiring Azure provisioning. No AppHost changes are needed. Fixes #​19617. (#​19998, backport of #​19843, @​eerhardt)

  • 🧩 Starter app generation could alter unrelated JavaScript values — Dynamic port replacement could also replace matching numeric literals in bundled JavaScript, including Bootstrap timing values. Port substitutions are now restricted to localhost: URLs, preserving the original library files while still configuring the requested ports. Fixes #​20030. (#​20110, backport of #​20031, @​bart-vmware, @​JamesNK)

  • 🍎 Updated the Aspire Homebrew cask for Homebrew 6.x — Replaced deprecated cask URL and post-install syntax with the supported equivalents, resolving compatibility issues with current Homebrew while preserving install-channel metadata. (#​20119, backport of #​19965, @​askpt, @​joperezr)

  • 🧪 Radius cloud-provider callback interfaces now carry the experimental diagnostic — IAwsRadiusProviderBuilder and IAzureRadiusProviderBuilder are now marked with ASPIRERADIUS003, matching the existing WithAwsProvider and WithAzureProvider methods. Code referencing these interfaces directly must now acknowledge the same experimental API diagnostic. (#​19874, @​sebastienros)


Full Changelog: v13.5.3...v13.5.4

Full commit: 9c1b401dd67746739044f68959cbf4d3d7af93a6

Commits viewable in compare view.

Updated Marten from 9.39.0 to 9.39.1.

Release notes

Sourced from Marten's releases.

9.39.1

What's Changed

Full Changelog: JasperFx/marten@V9.39.0...v9.39.1

Commits viewable in compare view.

Updated OpenTelemetry.Instrumentation.AspNetCore from 1.18.0 to 1.19.0.

Release notes

Sourced from OpenTelemetry.Instrumentation.AspNetCore's releases.

1.19.0

1.19.0-rc.1

1.19.0-beta.1

1.19.0-alpha.1

1.18.1

Commits viewable in compare view.

Updated OpenTelemetry.Instrumentation.Runtime from 1.18.0 to 1.19.0.

Release notes

Sourced from OpenTelemetry.Instrumentation.Runtime's releases.

1.19.0

1.19.0-rc.1

1.19.0-beta.1

1.19.0-alpha.1

1.18.1

Commits viewable in compare view.

Updated WolverineFx from 6.39.1 to 6.40.0.

Release notes

Sourced from WolverineFx's releases.

6.40.0

51 commits since V6.39.1. A minor release rather than a patch, because this wave carries new capability and not only fixes.

New capability

  • Capacity-aware agent assignment (#​3959) — agent distribution now accounts for node capacity rather than treating every node as interchangeable. Landed as @​mlh758's #​4297, then hardened in #​4596 and #​4598 to require a real load monitor, stop a shed draining the cluster, and hold pins across every distribution path. Note that the node-load advertisement is PostgreSQL-only until #​4593 lands for the other stores.
  • External table transport for Oracle (#​4482) — implemented by @​Trasvi in #​4558, with follow-ups in #​4574, #​4577 and #​4578. The shared ExternalTableTransportCompliance suite now holds Oracle, PostgreSQL, SQL Server, MySQL and Sqlite to the same bar.
  • A deduplication claim now rides the business transaction on Marten (#​4505), Polecat (#​4570) and Fisher (#​4571). The claim is enlisted in the same unit of work as the handler's own writes instead of being committed on a connection of its own and compensated with a release. A refusal that never commits therefore never claims the id, and there is no release left to mis-order.

Behaviour changes

  • An unknown tenant id answers 404 ProblemDetails instead of 500 (#​4516).
  • Concurrency failures can be mapped to 409 with a one-line opt-in (#​4512).
  • MissingNamedConnectionStringsException stays an InvalidOperationException (#​4527), and every named connection string is now validated in one pass at startup.
  • Wolverine's Kafka error handler composes with the user's instead of replacing it (#​4522).

Exception message wave

#​4511–#​4532 — 18 PRs making the framework's exceptions name a remedy rather than only a symptom: saga failures, handler discovery, SNS/Rabbit MQ/Azure Service Bus/Redis/SignalR configuration problems, oversized messages, unreadable HTTP bodies, and the transports' previously message-less exceptions.

Fixes

  • Stop reading steady-state throughput as a stuck recovery batch, and detect a genuinely stuck outbox from the head of the queue (#​4499).
  • Sweep expired handled envelopes on Cosmos DB, and make DeleteAllHandledAsync work (#​4509).
  • Bound SQLite's two reaps (#​4567).
  • Only ever write ASP.NET Core's endpoint data sources from the composition thread (#​4500).
  • Grandfather a group-affinity candidate per member rather than per partition (#​4562) — @​erdtsieck's #​4563, with blue/green Polecat coverage in #​4576.
  • Declare a module's ancillary store once per namespace (#​4507) — @​uniquelau's #​4508.
  • Apply an ISendMyself published from a projection side effect, on all three stores (#​4556) — built on @​erdtsieck's #​4557.
  • Reject conflicting sending and listening modes on shared listeners (#​4059) — built on @​tmorejon's #​4506.
  • Say "disabled tenant" when that is what happened, and actually refuse one (#​4586).
  • Stop the Redis protocol version header surviving a round trip (#​4595).
  • Do not treat a sticky-bound listen-only endpoint as a local send target (#​4510).
  • Scope Polecat's and Fisher's duplicate-message Discard() to the inbox table (#​4565).

Dependencies

Unchanged from 6.39.1 — Marten 9.35.0, Polecat 5.29.0, Fisher 1.10.0, Weasel 9.32.0, JasperFx 2.74.0. This release ships exactly what its CI has been green against; the pin bump follows separately.

Contributors

Thank you to everyone who contributed code to this release:

Commits viewable in compare view.

Updated WolverineFx.Http from 6.39.1 to 6.40.0.

Release notes

Sourced from WolverineFx.Http's releases.

6.40.0

51 commits since V6.39.1. A minor release rather than a patch, because this wave carries new capability and not only fixes.

New capability

  • Capacity-aware agent assignment (#​3959) — agent distribution now accounts for node capacity rather than treating every node as interchangeable. Landed as @​mlh758's #​4297, then hardened in #​4596 and #​4598 to require a real load monitor, stop a shed draining the cluster, and hold pins across every distribution path. Note that the node-load advertisement is PostgreSQL-only until #​4593 lands for the other stores.
  • External table transport for Oracle (#​4482) — implemented by @​Trasvi in #​4558, with follow-ups in #​4574, #​4577 and #​4578. The shared ExternalTableTransportCompliance suite now holds Oracle, PostgreSQL, SQL Server, MySQL and Sqlite to the same bar.
  • A deduplication claim now rides the business transaction on Marten (#​4505), Polecat (#​4570) and Fisher (#​4571). The claim is enlisted in the same unit of work as the handler's own writes instead of being committed on a connection of its own and compensated with a release. A refusal that never commits therefore never claims the id, and there is no release left to mis-order.

Behaviour changes

  • An unknown tenant id answers 404 ProblemDetails instead of 500 (#​4516).
  • Concurrency failures can be mapped to 409 with a one-line opt-in (#​4512).
  • MissingNamedConnectionStringsException stays an InvalidOperationException (#​4527), and every named connection string is now validated in one pass at startup.
  • Wolverine's Kafka error handler composes with the user's instead of replacing it (#​4522).

Exception message wave

#​4511–#​4532 — 18 PRs making the framework's exceptions name a remedy rather than only a symptom: saga failures, handler discovery, SNS/Rabbit MQ/Azure Service Bus/Redis/SignalR configuration problems, oversized messages, unreadable HTTP bodies, and the transports' previously message-less exceptions.

Fixes

  • Stop reading steady-state throughput as a stuck recovery batch, and detect a genuinely stuck outbox from the head of the queue (#​4499).
  • Sweep expired handled envelopes on Cosmos DB, and make DeleteAllHandledAsync work (#​4509).
  • Bound SQLite's two reaps (#​4567).
  • Only ever write ASP.NET Core's endpoint data sources from the composition thread (#​4500).
  • Grandfather a group-affinity candidate per member rather than per partition (#​4562) — @​erdtsieck's #​4563, with blue/green Polecat coverage in #​4576.
  • Declare a module's ancillary store once per namespace (#​4507) — @​uniquelau's #​4508.
  • Apply an ISendMyself published from a projection side effect, on all three stores (#​4556) — built on @​erdtsieck's #​4557.
  • Reject conflicting sending and listening modes on shared listeners (#​4059) — built on @​tmorejon's #​4506.
  • Say "disabled tenant" when that is what happened, and actually refuse one (#​4586).
  • Stop the Redis protocol version header surviving a round trip (#​4595).
  • Do not treat a sticky-bound listen-only endpoint as a local send target (#​4510).
  • Scope Polecat's and Fisher's duplicate-message Discard() to the inbox table (#​4565).

Dependencies

Unchanged from 6.39.1 — Marten 9.35.0, Polecat 5.29.0, Fisher 1.10.0, Weasel 9.32.0, JasperFx 2.74.0. This release ships exactly what its CI has been green against; the pin bump follows separately.

Contributors

Thank you to everyone who contributed code to this release:

Commits viewable in compare view.

Updated WolverineFx.Marten from 6.39.1 to 6.40.0.

Release notes

Sourced from WolverineFx.Marten's releases.

6.40.0

51 commits since V6.39.1. A minor release rather than a patch, because this wave carries new capability and not only fixes.

New capability

  • Capacity-aware agent assignment (#​3959) — agent distribution now accounts for node capacity rather than treating every node as interchangeable. Landed as @​mlh758's #​4297, then hardened in #​4596 and #​4598 to require a real load monitor, stop a shed draining the cluster, and hold pins across every distribution path. Note that the node-load advertisement is PostgreSQL-only until #​4593 lands for the other stores.
  • External table transport for Oracle (#​4482) — implemented by @​Trasvi in #​4558, with follow-ups in #​4574, #​4577 and #​4578. The shared ExternalTableTransportCompliance suite now holds Oracle, PostgreSQL, SQL Server, MySQL and Sqlite to the same bar.
  • A deduplication claim now rides the business transaction on Marten (#​4505), Polecat (#​4570) and Fisher (#​4571). The claim is enlisted in the same unit of work as the handler's own writes instead of being committed on a connection of its own and compensated with a release. A refusal that never commits therefore never claims the id, and there is no release left to mis-order.

Behaviour changes

  • An unknown tenant id answers 404 ProblemDetails instead of 500 (#​4516).
  • Concurrency failures can be mapped to 409 with a one-line opt-in (#​4512).
  • MissingNamedConnectionStringsException stays an InvalidOperationException (#​4527), and every named connection string is now validated in one pass at startup.
  • Wolverine's Kafka error handler composes with the user's instead of replacing it (#​4522).

Exception message wave

#​4511–#​4532 — 18 PRs making the framework's exceptions name a remedy rather than only a symptom: saga failures, handler discovery, SNS/Rabbit MQ/Azure Service Bus/Redis/SignalR configuration problems, oversized messages, unreadable HTTP bodies, and the transports' previously message-less exceptions.

Fixes

  • Stop reading steady-state throughput as a stuck recovery batch, and detect a genuinely stuck outbox from the head of the queue (#​4499).
  • Sweep expired handled envelopes on Cosmos DB, and make DeleteAllHandledAsync work (#​4509).
  • Bound SQLite's two reaps (#​4567).
  • Only ever write ASP.NET Core's endpoint data sources from the composition thread (#​4500).
  • Grandfather a group-affinity candidate per member rather than per partition (#​4562) — @​erdtsieck's #​4563, with blue/green Polecat coverage in #​4576.
  • Declare a module's ancillary store once per namespace (#​4507) — @​uniquelau's #​4508.
  • Apply an ISendMyself published from a projection side effect, on all three stores (#​4556) — built on @​erdtsieck's #​4557.
  • Reject conflicting sending and listening modes on shared listeners (#​4059) — built on @​tmorejon's #​4506.
  • Say "disabled tenant" when that is what happened, and actually refuse one (#​4586).
  • Stop the Redis protocol version header surviving a round trip (#​4595).
  • Do not treat a sticky-bound listen-only endpoint as a local send target (#​4510).
  • Scope Polecat's and Fisher's duplicate-message Discard() to the inbox table (#​4565).

Dependencies

Unchanged from 6.39.1 — Marten 9.35.0, Polecat 5.29.0, Fisher 1.10.0, Weasel 9.32.0, JasperFx 2.74.0. This release ships exactly what its CI has been green against; the pin bump follows separately.

Contributors

Thank you to everyone who contributed code to this release:

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Aspire.Hosting.JavaScript from 13.5.3 to 13.5.4
Bumps Aspire.Hosting.PostgreSQL from 13.5.3 to 13.5.4
Bumps Marten from 9.39.0 to 9.39.1
Bumps OpenTelemetry.Instrumentation.AspNetCore from 1.18.0 to 1.19.0
Bumps OpenTelemetry.Instrumentation.Runtime from 1.18.0 to 1.19.0
Bumps WolverineFx from 6.39.1 to 6.40.0
Bumps WolverineFx.Http from 6.39.1 to 6.40.0
Bumps WolverineFx.Marten from 6.39.1 to 6.40.0

---
updated-dependencies:
- dependency-name: Aspire.Hosting.JavaScript
  dependency-version: 13.5.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-and-patch
- dependency-name: Aspire.Hosting.PostgreSQL
  dependency-version: 13.5.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-and-patch
- dependency-name: Marten
  dependency-version: 9.39.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-and-patch
- dependency-name: Marten
  dependency-version: 9.39.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-and-patch
- dependency-name: OpenTelemetry.Instrumentation.AspNetCore
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-and-patch
- dependency-name: OpenTelemetry.Instrumentation.Runtime
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-and-patch
- dependency-name: WolverineFx
  dependency-version: 6.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-and-patch
- dependency-name: WolverineFx.Http
  dependency-version: 6.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-and-patch
- dependency-name: WolverineFx.Marten
  dependency-version: 6.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code labels Sep 24, 2026
@Niewski
Niewski merged commit 8c51be7 into main Sep 24, 2026
2 checks passed
@Niewski
Niewski deleted the dependabot/nuget/src/BallBank.Api/nuget-minor-and-patch-b12f02139a branch September 24, 2026 23:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

1 participant