Skip to content

Bump the nuget-minor-patch group with 27 updates#21

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/src/FlowSharp.Infrastructure/nuget-minor-patch-712117a9d8
Open

Bump the nuget-minor-patch group with 27 updates#21
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/src/FlowSharp.Infrastructure/nuget-minor-patch-712117a9d8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor

Updated AngleSharp from 1.5.0 to 1.5.2.

Release notes

Sourced from AngleSharp's releases.

1.5.2

Released on Sunday, July 5 2026

  • Fixed NodeIterator pre-removing steps to use the first following node (#​1260) @​ivandrofly
  • Fixed Range.IsCollapsed to also compare offsets (#​1259) @​ivandrofly
  • Fixed swapped comparison in Range.CompareBoundaryTo (#​1258) @​ivandrofly
  • Fixed Range.CopyContent to follow the DOM Standard (#​1257) @​ivandrofly
  • Fixed Range.ExtractContent to follow the DOM Standard (#​1256) @​ivandrofly
  • Added missing media attribute change detection on SVG style elements (#​1261) @​ivandrofly

Commits viewable in compare view.

Updated Jint from 4.9.3 to 4.13.0.

Release notes

Sourced from Jint's releases.

4.13.0

Jint 4.13.0 is a performance- and correctness-focused release. It brings a Proxy overhaul — trap dispatch rebuilt to forward with near-zero allocation, plus a new public API for implementing traps in .NET — extends the unboxed interpreter fast lanes to more operators and loop shapes, and cuts allocations on for..of, nested-function calls and array enumeration. A thorough pre-release review of everything since 4.12.0 also fixed several correctness bugs. No code changes are required to benefit.

Highlights

Proxy overhaul, and a CLR trap API. Proxy trap dispatch was rebuilt around a shared skeleton with lazy argument construction and pooled arrays, so a proxy with no matching trap forwards to its target with effectively zero allocation (#​2674, #​2675, #​2676). Proxies can now be implemented from .NET: Engine.Advanced.CreateProxy / CreateRevocableProxy accept a ProxyHandler whose virtual methods are the traps, with the same invariant enforcement as JavaScript handlers (#​2678). Several Proxy spec fixes came along — getPrototypeOf / setPrototypeOf with null prototypes (#​2668), the construct trap's argument array (#​2670), capturing [[Construct]] at creation (#​2669), and the get trap firing for a property named revoke (#​2667) — and the ObjectWrapper iterator helpers are hardened against foreign and revoked receivers (#​2681).

Interpreter fast lanes. New unboxed operand lanes for the arithmetic binary operators (#​2664) and an int32 fast lane for remainder (#​2671) remove per-iteration boxing; flag-proven casts use Unsafe.As on the hot paths (#​2673) and JsNumber.Create avoids a native fmod (#​2662). Strict-equality guards against undefined / null / typeof are fused (#​2658), member-expression identifier reads route through the identifier caches (#​2660), and the identifier slot cache is restructured hop-0-first (#​2689). The tight-loop fast lane now covers while and do-while bodies (#​2688).

Lower allocations. for..of over an array no longer allocates an iterator-result object per element (#​2700); per-call nested-function instantiation is allocation-free (#​2684); for-in over arrays enumerates dense indices lazily without materializing a key list (#​2656); and observation-only constraint checks are amortized so tight loops stay fast under a timeout (#​2672).

RegExp. Quantified groups without capture or lookaround hazards prefer the .NET Regex engine (#​2682), reused .NET adaptations adaptively upgrade to RegexOptions.Compiled (#​2690), and the custom engine's match timeout is enforced by an inline deadline rather than a thread-pool timer (#​2686).

Correctness (including a pre-release review). A review of everything since 4.12.0 fixed: a regex routing regression that silently truncated matches for nullable non-capturing quantified groups (#​2694) and a custom-engine bug dropping iterations for multi-atom quantified groups (#​2699); Proxy trap dispatch is now atomic against a mid-dispatch revoke (#​2696); top-level await of a .NET Task in a module (#​2665), plus prompt cancellation of the await drain (#​2697); the arguments object escaping a short-circuiting logical compound assignment un-materialized (#​2698); for-in now includes inherited enumerable index properties on Array.prototype (#​2655); and the memory limit stays exact in tight loops (#​2695).

Across the managed JavaScript engines for .NET, Jint 4.13.0 is the fastest engine on 17 of the 21 comparison scripts — and the fastest interpreter on all 21 — while allocating far less memory than the other engines; dromaeo-3d-cube is ~9% faster and dromaeo-string-base64 ~10% faster than 4.12.0. See the engine comparison benchmarks for the full table.

What's Changed

4.12.0

Jint 4.12.0 is a performance- and correctness-focused release. It completes the move to hidden-class shapes across the whole object model, extends the unboxed interpreter fast lanes to more operators and call shapes, and adds a layer of per-engine caching so re-executed scripts and re-created functions reuse their compiled metadata and environments. A pre-release review of everything since 4.11.0 also fixed several correctness regressions. No code changes are required to benefit.

Highlights

Object model — shapes everywhere. The hidden-class shape model now backs the built-in prototypes and constructors, TypedArrays, the global object, and Intl / Temporal (#​2580, #​2581, #​2582, #​2590, #​2595, #​2597). JSON.parse builds its result objects as shapes, so an array of like-shaped records costs one allocation per record instead of a property dictionary each (#​2634). Object literals inside generator/async frames and object spread {...src} adopt shapes too (#​2596, #​2648, #​2635), and a provably-simple constructor shapes its instances from the third construction (#​2636).

Interpreter fast lanes. New unboxed operand lanes for equality, bitwise, modulo-equality and sum-of-products expressions remove per-iteration boxing (#​2602, #​2604, #​2611, #​2628), and comparison operands are served from the validated global-descriptor cache (#​2603). Expression-only and if/else for-loop bodies run through a tight per-iteration cycle with a member-bound loop test (i < arr.length) (#​2605, #​2617, #​2623), env-less leaf calls run against the captured environment directly (#​2627), and functions that cannot observe their this skip this-binding (#​2626).

Caching & reuse. Nested-scope global reads and writes are served from a validated global-binding cache (#​2584, #​2625); hoisted function and class definitions, and the top-level statement handler tree, are reused across re-evaluations on an engine (#​2613, #​2615, #​2649); and for-of / for-in reuse a fixed-slot per-iteration environment, skipping per-iteration TDZ re-init where it is provably safe (#​2586, #​2632).

Lower allocations. A coverage campaign added benchmarks for common patterns the suite did not exercise and then closed the hotspots they surfaced (#​2630): resolved await chains and engine-internal promise reactions (#​2639), for-in enumeration (#​2640), throw/catch (#​2641), primitive number/boolean/bigint methods (no wrapper object, #​2642), and tagged templates (#​2638) all allocate far less.

Correctness. Fixes for sticky + global [Symbol.match] returning wrong results (#​2600), an unlabeled break escaping a labeled switch (#​2607), -0 in integer multiplication (#​2620), and raw property writes on shaped hosts (#​2591, #​2601). A pre-release review (#​2651) additionally fixed for-in re-enumerating a shadowed key (a mid-loop delete and a pooled-iterator reuse case), mapped-arguments writes being lost after the call returns (and duplicate-parameter mapping now follows the spec), and hardened the object-literal and built-in-shape paths.

Across the managed JavaScript engines for .NET, Jint 4.12.0 is the fastest engine on 17 of the 21 comparison scripts — and the fastest interpreter on all 21 — leading by up to ~5.4× over the next-fastest engine while allocating 2×–63× less memory than the closest competitor. See the engine comparison benchmarks for the full table.

What's Changed

4.11.0

Jint 4.11.0 is a performance-focused release. It completes the move to a hidden-class shape model for the object system and adds a family of unboxed interpreter fast lanes, so the most common patterns — object and array construction, property access, tight numeric loops, and eval — do less work and allocate far less memory, with no change to behavior.

Highlights

  • Object model. Object literals, hot constructor instances, and the built-in prototypes now use hidden-class shapes, and small objects store their properties inline in a single allocation (#​2548, #​2552, #​2553, #​2554, #​2555, #​2556, #​2557, #​2559). Property reads and writes are served by inline caches (#​2546, #​2558).
  • Interpreter fast lanes. Relational tests and plain/compound assignments against slot-stored numbers now run unboxed, removing per-iteration boxing from loops (#​2550, #​2566, #​2574, #​2577, #​2578). Strict eval runs in slot-backed environments (#​2565), direct-recursive calls pool their environments (#​2549), and Function-constructor instances reuse a definition-level environment (#​2579).
  • Lower memory. Function.prototype.toString source-text retention is now opt-in (#​2562), and the changes above cut allocations across the board — direct recursion, for example, allocates up to ~99% less.
  • Correctness. Fixes for async parameter binding after await (#​2567), Map iteration during mutation (#​2570), and ShadowRealm evaluation of super / new.target (#​2573).

Across the managed JavaScript engines for .NET, Jint 4.11.0 is the fastest on most object, string and regex workloads — 1.7–5× over the next-fastest engine — while allocating 2–63× less memory than the closest competitor. See the engine comparison benchmarks for the full table.

[!WARNING]
Function.prototype.toString() no longer returns source text by default. To cut memory use (#​2560), the engine no longer retains each parsed function's source string, so toString() now returns a function name() { [native code] } placeholder instead of the original source. If your scripts — or a library you host — depend on toString() returning real source, re-enable it with new Engine(options => options.RetainFunctionSourceText()) (equivalently Options.RetainFunctionSourceText = true, or the matching RetainFunctionSourceText flag on ScriptParsingOptions / ModuleParsingOptions and prepared scripts).

Performance caveat: turning it back on restores the previous memory behavior — every parsed function pins its full source string, so caching many or large prepared scripts can retain hundreds of MB of duplicated source (the retention that #​2560 was filed to fix). Enable it only when you actually need the source text.

What's Changed

New Contributors

Full Changelog: sebastienros/jint@v4.10.1...v4.11.0
... (truncated)

4.10.1

Overview

Jint 4.10.1 is a small follow-up to 4.10.0 that continues the memory-reduction work. Arrays no longer carry a dedicated PropertyDescriptor for their length (#​2540) and an extra PropertyDescriptor allocation on the data-property creation path was removed (#​2537), trimming GC pressure further with no code changes required. It also fixes a strict-mode spec gap where writing to a read-only array index failed to throw a TypeError (#​2542), and refreshes the engine-comparison benchmarks (#​2517) and dependencies (#​2545).

What's Changed

Full Changelog: sebastienros/jint@v4.10.0...v4.10.1

4.10.0

Overview

Jint 4.10.0 is a performance- and memory-focused release. The bulk of this cycle went into making the interpreter run faster and allocate less, with additional work on CLR interop speed and diagnostics, plus a handful of correctness and spec-compliance fixes.

If you execute the same scripts repeatedly, run interop-heavy workloads, or care about GC pressure, this release should give you a meaningful, no-code-changes-required speedup.

Highlights

Interpreter performance

  • New fast paths for object method calls (#​2510), computed dense-array reads/writes (#​2511), and global variable / x++ updates via version-gated inline caches (#​2507, #​2514).
  • Function-call overhead reduced: function-local numbers stored unboxed in environment slots (#​2499), FunctionDeclarationInstantiation skipped entirely when there's nothing to do (#​2502), lazy constructor .prototype creation (#​2512), and no more per-call closure allocation in EvaluateBody (#​2534).
  • A compilation cache for repeated eval and new Function sources (#​2503), and a fix for prepared scripts that were running slower than re-parsed source (#​2504).
  • Process-wide cache of compiled regex adaptations (#​2530) and a faster String.prototype.split with a string separator (#​2519).

Reduced allocations & memory footprint

  • Zero-copy views returned from large slice / substring / substr results, extended to bounded-waste substrings (#​2506, #​2518).
  • A pooled accumulator slashes intermediate allocations in array-building built-ins, extended to RegExp split, Iterator.toArray, and object enumeration (#​2524, #​2526).
  • Pooled for-loop iteration environments (#​2515), preserved dictionary capacity across pooled function-environment reuse (#​2528), and a raised fixed-slot environment cap (16 → 24 bindings) (#​2529).
  • Smaller runtime objects: JsDate shrunk by 8 bytes (#​2535) and ObjectInstance slimmed by relocating _privateElements to a per-engine weak table (#​2536).

CLR interop

  • Lower method-dispatch overhead and fewer allocations (#​2520), no per-access parameter-array allocation in indexer reads (#​2521), and an opt-in bounded cache for recently wrapped CLR objects (#​2522).
  • Customizable reported property keys for CLR objects, enabling for..in over wrapped objects (#​2516).
  • Richer interop resolution errors that include the target type, arguments, and candidate signatures — gated behind an opt-in option, with the CLR type exposed to the host (#​2525, #​2527).

Correctness & spec compliance

  • Fixed completion value being clobbered by a re-entrant Evaluate() during module execution (#​2493).
  • Fixed runtime type-member writes for CLR wrappers (#​2496) and DefaultTypeConverter.Convert bypassing subclass TryConvert overrides (#​2498).
  • Fixed integer fast-path overflows and compound-assignment spec divergences (#​2497).
  • Updated the Test262 suite and fixed promise-combinator handling of non-thenables (#​2500).

⚠️ Upgrading from 4.9.2 or earlier

4.10.0 contains no new breaking changes, but if you skip past 4.9.3 note its host-side breaking change: Error.prototype.stack became a get/set accessor on %Error.prototype% (it is no longer an own property of each error instance), so host code reading the trace via ObjectInstance.TryGetValue("stack", …) now gets undefined — use errorObject.Get("stack") instead. See the v4.9.3 release notes for details (#​2489).


What's Changed

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Diagnostics.EntityFrameworkCore from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.AspNetCore.Diagnostics.EntityFrameworkCore's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Identity.EntityFrameworkCore from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.AspNetCore.Identity.EntityFrameworkCore's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Mvc.Testing from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.AspNetCore.Mvc.Testing's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.CodeAnalysis.CSharp from 5.3.0 to 5.6.0.

Release notes

Sourced from Microsoft.CodeAnalysis.CSharp's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.CodeAnalysis.CSharp.Workspaces from 5.3.0 to 5.6.0.

Updated Microsoft.CodeAnalysis.Workspaces.MSBuild from 5.3.0 to 5.6.0.

Release notes

Sourced from Microsoft.CodeAnalysis.Workspaces.MSBuild's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Data.SqlClient from 7.0.1 to 7.0.2.

Release notes

Sourced from Microsoft.Data.SqlClient's releases.

7.0.2

This update brings the following changes since the 7.0.1 release:

Important — package version alignment: Starting with 7.0.2, the Microsoft.Data.SqlClient driver and its companion packages share a single aligned version. The following packages now ship together as 7.0.2:

  • Microsoft.Data.SqlClient
  • Microsoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProvider
  • Microsoft.Data.SqlClient.Extensions.Azure
  • Microsoft.Data.SqlClient.Extensions.Abstractions
  • Microsoft.Data.SqlClient.Internal.Logging

(Microsoft.SqlServer.Server continues to version independently and remains at 1.0.0.)

Applications must reference the same versions of Microsoft.Data.SqlClient and its extensions for best compatibility. In particular, applications that reference Microsoft.Data.SqlClient.Extensions.Azure must upgrade it to 7.0.2 when upgrading Microsoft.Data.SqlClient to 7.0.2.

Breaking change (.NET Framework only): As part of this alignment, the AssemblyVersion of Microsoft.Data.SqlClient.Extensions.Azure, Microsoft.Data.SqlClient.Extensions.Abstractions, and Microsoft.Data.SqlClient.Internal.Logging changed from 1.0.0.0 to 7.0.0.0 (the Microsoft.Data.SqlClient and Microsoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProvider assembly versions are unchanged). On .NET Framework, AssemblyVersion is part of the strong-name identity, so applications that drop these assemblies into an existing deployment without rebuilding must rebuild against the 7.0.2 packages (or add binding redirects). Applications on .NET / .NET Core are not affected.

Companion package release notes

The following companion packages ship aligned as 7.0.2. See their individual release notes for package-specific changes (including the Microsoft.Data.SqlClient.Extensions.Azure WAM broker support):

Fixed

  • Fixed a NullReferenceException in SqlCommand.Cancel(). The diagnostic message built during cancellation dereferenced the active connection directly; it now uses a null-conditional access so cancellation no longer throws when the connection has already been torn down.
    (#​4372,#​4373)

  • Fixed a NullReferenceException in SqlDataReader when calling GetBytes/GetChars with a null destination buffer. The argument-validation path that constructs the InvalidDestinationBufferIndex exception now guards against the null buffer so the correct ArgumentException is surfaced instead of an NRE.
    (#​4159,#​4206)

  • Fixed Always Encrypted column master key signature verification incorrectly reusing cached results. The SignatureVerificationCache lookup logic was corrected so signature verification outcomes are cached and retrieved against the correct key, preventing stale or mismatched verification results.
    (#​4339,#​4343)

Changed

Hardened TDS token parsing with data-length bounds checks

What Changed:

  • Added bounds checking when parsing TDS token and feature-extension-acknowledgment data lengths. The parser now validates the declared length of incoming token data against the available buffer before reading, rejecting malformed or out-of-range length values instead of reading past the intended boundary.
    (#​4340,#​4358)

Who Benefits:

  • All consumers benefit from improved resilience against malformed or hostile TDS responses. A server (or man-in-the-middle) sending an invalid token length can no longer drive the parser to read beyond the declared payload.

Impact:
... (truncated)

Commits viewable in compare view.

Updated Microsoft.Data.Sqlite from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.Data.Sqlite's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.Design from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.EntityFrameworkCore.Design's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.Sqlite from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.EntityFrameworkCore.Sqlite's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.SqlServer from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.EntityFrameworkCore.SqlServer's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.Tools from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.EntityFrameworkCore.Tools's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.NET.Test.Sdk from 18.6.0 to 18.8.1.

Release notes

Sourced from Microsoft.NET.Test.Sdk's releases.

18.8.1

What's Changed

Full Changelog: microsoft/vstest@v18.8.0...v18.8.1

18.8.0

What's Changed

Full Changelog: microsoft/vstest@v18.7.0...v18.8.0

18.7.0

What's Changed

New Contributors

Full Changelog: microsoft/vstest@v18.6.0...v18.7.0

Commits viewable in compare view.

Updated Microsoft.SemanticKernel from 1.77.0 to 1.78.0.

Release notes

Sourced from Microsoft.SemanticKernel's releases.

1.78.0

Changes:

  • 35ba23e1b3092271c778ca057afe1a796e16e70e .Net: Update package version to 1.78.0 (#​14142)
  • e6c9673684ca03621885083faff1644e1f42695e .Net: Disable automatic HTTP redirects in HttpPlugin and WebFileDownloadPlugin default clients (#​14132)
  • f25753be0a126138d2eea39b0ca2985252dde25a Bump Scriban from 7.2.0 to 7.2.5 to fix NU1902 vulnerability (#​14133)
  • dfc5227227352e7cf4b11de1d9b8e49ebc7b43ff .Net: Update .NET SDK to 10.0.301 (#​14119)
  • cf9af8b966841e8f16d528bd0f2c69c51213b68d .Net: Bump axios to 1.16.0 and form-data to 4.0.6 in /dotnet/samples/Demos/ProcessFrameworkWithSignalR (#​13858)
See More
  • e99c633fba9e4005bdb9b90a1f5441945b781040 .Net: Harden file path validation in Core, Document, and Web plugins (#​14118)
  • 99d1953e935bd88a4cc993cbad9485703734f1b5 Bump axios from 1.13.2 to 1.16.0 in /dotnet/samples/Demos/ProcessFrameworkWithSignalR/src/ProcessFramework.Aspire.SignalR.ReactFrontend (#​14044) [ #​10795, #​10822, #​10825, #​10729, #​7378, #​10745, #​10810, #​10802, #​6485, #​10680, #​6897, #​10794, #​10800, #​6241, #​10708, #​10819, #​7149, #​10772, #​10806, #​7260, #​10787, #​10724, #​7276, #​7414, #​6389, #​6460, #​10833, #​10588, #​7419, #​10820, #​10791, #​10796, #​10821, #​10782, #​10759, #​10804, #​10785, #​10813, #​10814, #​10790, #​10834 ]
  • 82f244233b89d38bf5e424ca409caa46f14490e6 .Net: Update SK to use MEVD packages and move MEVD projects out of main solution (#​14117)
  • 8ce2bcc07f0ce5e56052ffd4abd0332cc8fc08e5 .Net: Bump Aspire.Hosting.Azure.CognitiveServices from 13.0.0 to 13.3.0 (#​13996)
  • 20be253d7b4a41c8943f36addd8b6365bdcf7299 .Net: Bump esbuild, @​vitejs/plugin-react, vite, and transitive lockfile deps in /dotnet/samples/Demos/ProcessFrameworkWithSignalR/src/ProcessFramework.Aspire.SignalR.ReactFrontend (#​14070)
  • 445fd0ea5364622d30069510f639032ecea6eaff .Net: Bump Aspire.Azure.Search.Documents from 9.5.1 to 13.3.0 (#​13994)
  • 367c75f4ff972e7a2281dcae4bd74800c5eef9eb .Net: Bump minimatch from 3.1.2 to 3.1.5 in /dotnet/samples/Demos/ProcessWithCloudEvents/ProcessWithCloudEvents.Client (#​13604)
  • 6209c77fd52d6ff99d7797d66639055b36a91ae3 .Net: Bump @​babel/core from 7.26.10 to 7.29.7 in /dotnet/samples/Demos/ProcessWithCloudEvents/ProcessWithCloudEvents.Client (#​14083) [ #​18014, #​18001, #​17998, #​17992, #​17974, #​17923, #​17931, #​17915, #​17788, #​17739, #​17606, #​17592, #​17589 ]
  • 1ad0b7501bd9c8f8dfbafb7c1aa69fab1ba4cd28 Bump Aspire.Hosting.AppHost from 13.0.0 to 13.3.0 (#​13995)
  • 56422ada8aa95702aab5c969805c3395dd2f5022 .Net: Bump follow-redirects from 1.15.11 to 1.16.0 in /dotnet/samples/Demos/ProcessFrameworkWithSignalR/src/ProcessFramework.Aspire.SignalR.ReactFrontend (#​13877)
  • a5e8f9b43230675c86dcb7c3ff5021914537f8be .Net: Bump form-data from 4.0.5 to 4.0.6 in /dotnet/samples/Demos/ProcessFrameworkWithSignalR/src/ProcessFramework.Aspire.SignalR.ReactFrontend (#​14082)
  • 7fd75c3c73ac84106ce2883bae32b50c99378e40 .Net: fix: prevent duplicate "null" in JSON Schema type arrays for nullable parameters (#​13635) [ #​13527 ]
  • f8c757b218cfe70cd9bc0d921eb0828d290cbe56 Fix MessagePack high severity vulnerability (#​14079)

This list of changes was auto generated.

Commits viewable in compare view.

Updated ModelContextProtocol from 1.4.0 to 1.4.1.

Release notes

Sourced from ModelContextProtocol's releases.

1.4.1

This release backports a memory-leak fix for HTTP/SSE-based MCP servers. StreamableHttpServerTransport now releases its Server-Sent Events response stream reference as soon as a GET request ends, instead of holding it until the session is disposed via explicit DELETE or idle timeout. Long-lived SSE clients that disconnect without sending DELETE no longer pin the underlying Kestrel connection and its associated memory-pool buffers (~20 MiB per session), preventing the sustained memory growth that could accumulate under connect/disconnect churn.

What's Changed

  • Release SSE response stream reference when GET request ends #​1628 by @​halter73 (co-authored by @​joelmforsyth @​Copilot)

Acknowledgements

  • @​slomangino123 submitted issue #​766 (resolved by #​1628)

Full Changelog: modelcontextprotocol/csharp-sdk@v1.4.0...v1.4.1

Commits viewable in compare view.

Updated MudBlazor from 9.5.0 to 9.7.0.

Release notes

Sourced from MudBlazor's releases.

9.7.0

What's Changed

Breaking Changes

New Features

Bug Fixes

Other Changes

New Contributors

Full Changelog: MudBlazor/MudBlazor@v9.6.0...v9.7.0

9.6.0

What's Changed

New Features

Bug Fixes

New Contributors

Commits viewable in compare view.

Updated MySqlConnector from 2.6.0 to 2.6.1.

Release notes

Sourced from MySqlConnector's releases.

2.6.1

  • Fix GHSA-473q-m89c-ghf8: MitM password disclosure in zero-configuration TLS mode.
  • Fix MySqlCommand.Prepare with INSERT INTO ... RETURNING: #​1652.
  • Thanks to @​rusher for contributions to this release.

Commits viewable in compare view.

Updated Npgsql.EntityFrameworkCore.PostgreSQL from 10.0.2 to 10.0.3.

Release notes

Sourced from Npgsql.EntityFrameworkCore.PostgreSQL's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated OpenTelemetry.Exporter.Console from 1.15.3 to 1.17.0.

Release notes

Sourced from OpenTelemetry.Exporter.Console's releases.

1.17.0

For highlights and announcements pertaining to this release see: Release Notes > 1.17.0.

The following changes are from the previous release 1.17.0-rc.1.

... (truncated)

1.17.0-rc.1

The following changes are from the previous release 1.16.0.

  • NuGet: OpenTelemetry v1.17.0-rc.1

    • Fixed a metric point reclaim data race on CPU ARM architectures.
      (#​7401)

    • The library is now marked as trim and AOT compatible.
      (#​7441)

    • Replaced the vendored copy of
      EnvironmentVariablesConfigurationProvider with a direct
      Microsoft.Extensions.Configuration.EnvironmentVariables package dependency.
      Consumers gain automatic pickup of upstream bug fixes and security patches;
      no public API or behavioural change.
      (#​7146)

    • Added a verbose OpenTelemetry-Sdk self-diagnostics event that is emitted
      when an activity is dropped because its local (in-process) parent is not
      recorded.
      (#​7427)

    • Added support for a Schema URL on Resource instances.
      (#​7472)

    • Fixed a metric storage leak that occurred when meters and instruments were
      repeatedly created and disposed.
      (#​7466)

    • Added ExcludedTagKeys property to MetricStreamConfiguration to support
      excluding specific tag keys from metric streams.
      (#​7373)

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Api v1.17.0-rc.1

    • Fixed TraceContextPropagator to normalize empty tracestate header values
      to null when extracting trace context.
      (#​7407,
      #​7433)

    • The library is now marked as trim and AOT compatible.
      (#​7441)

    • Experimental (pre-release builds only): Updated EnvironmentVariableCarrier.Get
      to read only the normalized environment variable name, following the updated
      environment variable carrier specification.
      Non-normalized carrier keys are no longer matched, even when they would
      normalize to the requested key.
      ... (truncated)

1.17.0-beta.1

The following changes are from the previous release 1.16.0-beta.1.

Description has been truncated

Bumps AngleSharp from 1.5.0 to 1.5.2
Bumps Jint from 4.9.3 to 4.13.0
Bumps Microsoft.AspNetCore.Diagnostics.EntityFrameworkCore from 10.0.8 to 10.0.10
Bumps Microsoft.AspNetCore.Identity.EntityFrameworkCore from 10.0.8 to 10.0.10
Bumps Microsoft.AspNetCore.Mvc.Testing from 10.0.8 to 10.0.10
Bumps Microsoft.CodeAnalysis.CSharp from 5.3.0 to 5.6.0
Bumps Microsoft.CodeAnalysis.CSharp.Workspaces from 5.3.0 to 5.6.0
Bumps Microsoft.CodeAnalysis.Workspaces.MSBuild from 5.3.0 to 5.6.0
Bumps Microsoft.Data.SqlClient from 7.0.1 to 7.0.2
Bumps Microsoft.Data.Sqlite from 10.0.8 to 10.0.10
Bumps Microsoft.EntityFrameworkCore.Design from 10.0.8 to 10.0.10
Bumps Microsoft.EntityFrameworkCore.Sqlite from 10.0.8 to 10.0.10
Bumps Microsoft.EntityFrameworkCore.SqlServer from 10.0.8 to 10.0.10
Bumps Microsoft.EntityFrameworkCore.Tools from 10.0.8 to 10.0.10
Bumps Microsoft.NET.Test.Sdk from 18.6.0 to 18.8.1
Bumps Microsoft.SemanticKernel from 1.77.0 to 1.78.0
Bumps ModelContextProtocol from 1.4.0 to 1.4.1
Bumps MudBlazor from 9.5.0 to 9.7.0
Bumps MySqlConnector from 2.6.0 to 2.6.1
Bumps Npgsql.EntityFrameworkCore.PostgreSQL from 10.0.2 to 10.0.3
Bumps OpenTelemetry.Exporter.Console from 1.15.3 to 1.17.0
Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.15.3 to 1.17.0
Bumps OpenTelemetry.Extensions.Hosting from 1.15.3 to 1.17.0
Bumps OpenTelemetry.Instrumentation.AspNetCore from 1.15.2 to 1.17.0
Bumps OpenTelemetry.Instrumentation.Http from 1.15.1 to 1.17.0
Bumps OpenTelemetry.Instrumentation.Runtime from 1.15.1 to 1.17.0
Bumps System.Text.Json from 10.0.8 to 10.0.10

---
updated-dependencies:
- dependency-name: AngleSharp
  dependency-version: 1.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Jint
  dependency-version: 4.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.AspNetCore.Diagnostics.EntityFrameworkCore
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.AspNetCore.Identity.EntityFrameworkCore
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.AspNetCore.Identity.EntityFrameworkCore
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.AspNetCore.Mvc.Testing
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.CodeAnalysis.CSharp
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.CodeAnalysis.CSharp.Workspaces
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.CodeAnalysis.Workspaces.MSBuild
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.Data.SqlClient
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.Data.Sqlite
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.EntityFrameworkCore.Design
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.EntityFrameworkCore.Design
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.EntityFrameworkCore.Design
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.EntityFrameworkCore.Design
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.EntityFrameworkCore.Design
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.EntityFrameworkCore.Sqlite
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.EntityFrameworkCore.Sqlite
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.EntityFrameworkCore.Sqlite
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.EntityFrameworkCore.SqlServer
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.EntityFrameworkCore.SqlServer
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.EntityFrameworkCore.Tools
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: Microsoft.SemanticKernel
  dependency-version: 1.78.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: ModelContextProtocol
  dependency-version: 1.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: MudBlazor
  dependency-version: 9.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: MySqlConnector
  dependency-version: 2.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Npgsql.EntityFrameworkCore.PostgreSQL
  dependency-version: 10.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Npgsql.EntityFrameworkCore.PostgreSQL
  dependency-version: 10.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: OpenTelemetry.Exporter.Console
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: OpenTelemetry.Extensions.Hosting
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: OpenTelemetry.Instrumentation.AspNetCore
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: OpenTelemetry.Instrumentation.Http
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: OpenTelemetry.Instrumentation.Runtime
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: System.Text.Json
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants