Bump the nuget-minor-patch group with 4 updates - #84
Merged
Merged
Conversation
Bumps FluentAssertions from 8.10.0 to 8.11.0 Bumps Microsoft.NET.Test.Sdk from 18.10.0 to 18.10.1 Bumps NUnit.Analyzers from 4.14.0 to 4.15.0 Bumps Trax.Core.Testing from 1.7.0 to 1.7.1 --- updated-dependencies: - dependency-name: FluentAssertions dependency-version: 8.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-minor-patch - dependency-name: Microsoft.NET.Test.Sdk dependency-version: 18.10.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: NUnit.Analyzers dependency-version: 4.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-minor-patch - dependency-name: Trax.Core.Testing dependency-version: 1.7.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Theauxm
added a commit
that referenced
this pull request
Sep 17, 2026
The heal workflow has never landed a commit. On #84 it regenerated the lockfile correctly and was then rejected outright: GH013: Repository rule violations found for refs/heads/dependabot/nuget/... - Changes must be made through a pull request. - Commits must have verified signatures. A plain `git commit` in a runner has no signing key. It now writes through the createCommitOnBranch GraphQL mutation instead, which GitHub signs itself, so the heal lands Verified like Dependabot's own commits and no signing key has to exist in CI. The org ruleset still has to stop requiring a pull request on dependabot/** for the write to be allowed at all; the signature rule can stay. It keeps authenticating with GITHUB_TOKEN rather than moving to an App token or a PAT. Either of those would avoid the approval click described below, but both mean a long-lived credential in Dependabot secrets, and an App private key never expires and can mint write tokens for every repo it is installed on. GITHUB_TOKEN stores nothing. The trade is one "Approve and run" press per healed PR, on a visit already being made to merge it. Beyond the write: Dependabot rewrites project files on a grouped bump. When the transitive graph resolves one package at different versions across projects, it adds <PackageReference ... VersionOverride="..."> to projects that never referenced it, several pinned to the version being bumped away from. Nothing reverted those, so lockfiles regenerated on top of the injection. The revert is re-derived with git in the committing job rather than trusted from the patch, so the job that runs dependency code still hands over nothing but lockfiles. The regenerating restore now passes -p:NuGetAudit=false. Directory.Build.props promotes NU1901-NU1904 to errors, so an advisory anywhere in the graph aborted the regeneration, which is precisely the state a security bump arrives in. The PR build still audits. On the config side, csharpier and PublicApiGenerator are ignored. Each has to move in one commit with the artefact it invalidates -- the repo-wide format and the PublicApi baseline -- which a bot PR cannot do, so it just leaves the check failing every time. Roslyn moves to its own group so that when its bump does need a human it does not take the rest of the week's updates with it, and the PR limit drops to three.
Member
|
@dependabot rebase |
Contributor
Author
|
Dependabot attempted to update this pull request, but because the branch |
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated FluentAssertions from 8.10.0 to 8.11.0.
Release notes
Sourced from FluentAssertions's releases.
8.11.0
What's Changed
New features
ThatSatisfyfor methods and properties by @jnyrup in AddThatSatisfyfor methods and properties fluentassertions/fluentassertions#3257Improvements
Fixes
HavePropertyonJsonArrayby @jnyrup in Fix exception onHavePropertyonJsonArrayfluentassertions/fluentassertions#3295Documentation
Others
string.Formaton failure by @jnyrup in Correct the arguments passed tostring.Formaton failure fluentassertions/fluentassertions#3325New Contributors
Full Changelog: fluentassertions/fluentassertions@8.10.0...8.11.0
Commits viewable in compare view.
Updated Microsoft.NET.Test.Sdk from 18.10.0 to 18.10.1.
Release notes
Sourced from Microsoft.NET.Test.Sdk's releases.
18.10.1
What's Changed
Full Changelog: microsoft/vstest@v18.10.0...v18.10.1
Commits viewable in compare view.
Updated NUnit.Analyzers from 4.14.0 to 4.15.0.
Release notes
Sourced from NUnit.Analyzers's releases.
4.15.0
NUnit Analyzers 4.15 - September 12, 2026
This release of the NUnit Analyzers adds support for the new numeric types that will
be supported in NUnit 5. The release also improves
NUnit1027by inspecting base fixtures,and
NUnit1028by supportingIAsyncDisposable.DisposeAsyncin addition to theexisting
IDisposable.Dispose. The release also includes bug fixes and dependency updates.The release contains contributions from the following users (in alphabetical order):
Issues Resolved
Features and Enhancements
[CancelAfter]inherited from a base fixture[TestCaseSource]CA1812 suppressionBugs
recordscrash theNonNullableFieldOrPropertyIsUninitializedSuppressoranalyzerTooling, Process, and Documentation
Commits viewable in compare view.
Updated Trax.Core.Testing from 1.7.0 to 1.7.1.
Release notes
Sourced from Trax.Core.Testing's releases.
1.7.1
1.7.1 (2026-09-16)
Bug Fixes
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions