Update all non-major dependencies - #53
Open
renovate[bot] wants to merge 2 commits into
Open
renovate[bot] wants to merge 2 commits into
renovate[bot] wants to merge 2 commits into
Conversation
renovate
Bot
force-pushed
the
renovate/all-non-major-dependencies
branch
from
September 15, 2026 11:47
fad3b69 to
a522e48
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
25.9.5→25.9.619.2.18→19.3.019.2.5→19.3.010.0.11→10.0.1210.0.11→10.0.1218.9.0→18.10.07.6.1→7.7.03.20.0→3.21.03.22.03.20.0→3.21.03.22.03.20.0→3.21.03.22.010.0.400→10.0.40119.2.8→19.3.019.2.8→19.3.08.2.2→8.3.0Release Notes
dotnet/dotnet (Microsoft.AspNetCore.Authentication.OpenIdConnect)
v10.0.12microsoft/vstest (Microsoft.NET.Test.Sdk)
v18.10.0What's Changed
vstest.consoleand datacollector by @nohwnd in #16201Full Changelog: microsoft/vstest@v18.9.0...v18.10.0
openiddict/openiddict-core (OpenIddict.Server.AspNetCore)
v7.7.0Compare Source
This release introduces the following changes:
OpenIddict.Quartzpackage now references the 4.0 version of Quartz.NET. See https://www.quartz-scheduler.net/documentation/quartz-4.x/migration-guide.html for more information about Quartz.NET 4.0.The
audclaim in client assertions can now be represented as a JSON array, as allowed by the recent versions of the Updates to OAuth 2.0 JSON Web Token (JWT) Client Authentication and Assertion-Based Authorization Grants specification.The
OpenIddict.Client.WebIntegrationpackage now supports JoinRpg (thanks @leotsarev! ❤️)grant_type=urn:ietf:params:oauth:grant-type:device_codetoken requests that don't include a client identifier are now rejected earlier by the OpenIddict server stack.The
net9.0-android,net9.0-ios,net9.0-maccatalystandnet9.0-macostarget framework monikers are no longer supported by Microsoft and have been removed from theOpenIddict.Client.SystemIntegrationpackage and theOpenIddictmetapackage. Users of theOpenIddict.Client.SystemIntegrationpackage are invited to migrate to .NET 10.0.All the .NET and third-party dependencies have been updated to their latest version.
The
System.Interactive.Asyncdependency (used only on .NET Framework and .NET Standard) was downgraded to 3.2.0 to fix aTypeLoadExceptionthat prevented using the OpenIddict Entity Framework Core 2.3 stores on .NET Framework after migrating to OpenIddict 7.6.0.quartznet/quartznet (Quartz)
v3.21.0Quartz.NET 3.21.0 carries the three fixes held back from 3.20.1 because each needed a small addition to the public surface or changed what a running scheduler does. All three were found while 4.0 was being finished; each is as old as 3.x. The public API grows by two interfaces on one class and nothing else; the schema is 3.20's. Three of the changes alter behaviour, each marked Behavior change worth noting below.
What changed
ResumeAllclears every paused trigger group, not only the ones with triggers — the persistent store resumed the groups it found inQRTZ_TRIGGERSand then deleted only its all-groups marker, so a group paused while it held no triggers kept itsQRTZ_PAUSED_TRIGGER_GRPSrow and went on pausing whatever was scheduled into it afterwards. Pausing a group before anything is scheduled into it is a documented use of the exact-name matcher, so this was a row the store wrote on purpose and could not take back. The trailing delete now takes every group, asRAMJobStorehas always done. (#3721, #3742, port off76b04a)ResumeAll.RedisSemaphoreopened aConnectionMultiplexeron the first lock and kept it, with its heartbeat, for the life of the process, because nothing on the store's shutdown path reached the lock handler andISemaphorehad no member that meant "we are done". On a branch that targetsnetstandard2.0andnet462an interface cannot gain a default member, soJobStoreSupport.Shutdownnow disposes a lock handler that implementsIAsyncDisposableorIDisposable, after the misfire handler, the cluster manager and the connection manager have stopped, logging and continuing if that throws;RedisSemaphoreimplements both and closes the multiplexer it opened. (#3721, #3742, port of #3639)ISemaphorethat implements either interface is now disposed at shutdown.Task.Delayrefuses anything longer than about 49.7 days on .NET and about 24.9 days on .NET Framework, with anArgumentOutOfRangeExceptionnaming a parameter calleddelay, and every duration Quartz waits out that way was accepted unchecked and reported later from wherever the wait happened.MisfireHandlerFrequency,MisfireThreshold(when it is also the handler's sleep),ClusterCheckinInterval,DbRetryInterval,TransientRetryInterval, the row-lock handlers'RetryPeriod,StartDelayed's argument andQuartzHostedServiceOptions.StartDelaynow name the setting, the ceiling and the value at configuration time. The ceiling is per target framework, held to whatTask.Delayactually accepts by a test. (#3721, #3742, port of #3577)Public API — additive only
Quartz.Extensions.Redis:RedisSemaphoreimplementsIAsyncDisposableandIDisposable.Upgrading
dotnet add package Quartz --version 3.21.0. Nothing to migrate. The 4.0 line is the current major; the 4.x migration guide is the way there, and 4.0.1 made the upgrade one a dependency bot can offer.Full changelog: quartznet/quartznet@v3.20.1...v3.21.0
v3.20.1Quartz.NET 3.20.1 is a maintenance release: every change is a bug fix, the public API is untouched (the baselines did not move), and the schema is 3.20's. Most of it was found while 4.0 was being finished and rehearsed — a fix that turned out to be as old as 3.x was ported here rather than left on the newer line — and one item comes from a production application's 3.19.1 → 4.0 upgrade that also read on 3.x. Eight of the fixes change what a running scheduler does, each marked Behavior change worth noting below.
What changed
Landed on the branch since 3.20.0:
DailyTimeIntervalTriggerstored through the default Newtonsoft path reads back again —TimeOfDayhas no parameterless constructor, so with the trigger converters off (the default)EndTimeOfDaythrew "Unable to find a constructor" andStartTimeOfDaysilently read back as midnight. A converter scoped toTimeOfDay-typed members reads both forms; nothing about what is written changed, so every blob a released 3.20 wrote is one this reads. (9ee33fec17, fixes #3508)StartTimeUtckept its milliseconds while the fire times are counted in whole seconds, so a start of22:50:00.68could produce a first fire at22:50:00.000. Start and end are rounded down to the second when set, asCronTriggerImplalways did. (cc051a7788, #3386)RAMJobStoreand as a permanentCOMPLETErow in the ADO store. Both stores finish it now. (0af9431d3e, #3507)[DisallowConcurrentExecution]job is neither acquired nor swept, so the completion that unblocks it is the first thing that can settle its missed fire time;RAMJobStorenow does whatJobStoreSupport.RecoverUnblockedMisfiresalways did. (c9d8658a35, #3463)RAMJobStorewrotePausedoverError, so a failed trigger vanished from every listing once its group was paused andResetTriggerFromErrorStatehad nothing to reset. It now pauses only what the ADO store pauses: waiting, acquired and blocked triggers. (a56a16ca0c)RescheduleJobadvanced a never-fired repeating simple trigger's start time past a next fire time it kept, so it fired at the stale time and again at its start. (3e086091fc, #3554)overwrite-existing-dataon, and a repeating trigger that starts now fired twice milliseconds apart. (f25080cef6, #3554)Dictionary<string, string>job-data value written by the Newtonsoft package carried a$typethe System.Text.Json reader handed back as an entry, and one written by System.Text.Json came back from Json.NET as aJObject. Both readers read both shapes; neither writer changed. (83ba80ce79, part of #3582)QRTZ_SIMPROP_TRIGGERStoo — a database missing only that table passed validation and failed on the first calendar-interval, daily-time-interval or recurrence trigger insert. (b33c70487b, #3564)4b3c43a90e); untagged builds from the branch say 3.20 (0e2f6bcf31); the XML scheduling integration test opens its own fixture's data source (4c07210199, #3573).Ported from 4.0:
JobToBeExecutedescaped as itself rather than the exception the run shell catches, soTriggeredJobCompletewas never reached: the trigger stayed acquired and, for a[DisallowConcurrentExecution]job, every sibling trigger stayed blocked; the firing was also listed as executing for the life of the process. (port of #3502)IDX_QRTZ_T_NFT_ST_MISFIRE, whose second column is compared with<>and stops the seek dead. Measured on 4.x against 100,000 triggers: the count 111 ms → 0.7 ms, the sweep 66 ms → 0.7 ms. No schema change. (port of #3608)RescheduleJobandUpdateTriggerDetailson the ADO store resolved the job's class to decide whether the new trigger could run, and failed in an administration node without the assembly. Both read the job's two attribute flags fromQRTZ_JOB_DETAILSnow, so the decision is right without the class and a placeholderITypeLoadHelper— which decided that question by whether the placeholder carried the attribute — is no longer needed. (port of #3705)40001,40P01;40002excepted) is transient. Firebird reports a write conflict that way withIsTransientfalse, andMySql.Dataits 1213 deadlock. (port of #3454)SimpleTriggerinterval finer than a millisecond was stored as0, read back as zero, and left the trigger inACQUIREDfor good behind a divide-by-zero the store logged and swallowed. It is refused on write now, naming the trigger and the column;RAMJobStorekeeps accepting it. (port of #3673)List<string>or a nested object serialized happily and threw on the next read with the blob already in the database, and every later acquisition of the trigger failed on it. A value that would be stored as a JSON array, or as an object other than aDictionary<string, string>, is refused before the first byte is written, naming the entry and its type. Anything stored as a number or a string — every numeric type,DateTime,Guid,byte[],Uri— still round-trips exactly as before. (port of #3495)JsonSerializationExceptionat store time, where it used to be a blob the next read failed on. The refusal also covers three shapes that did not throw before but never came back as themselves either — a non-genericHashtable, an object whose properties are all strings, and aJobDataMapnested inside aJobDataMap— each of which the reader handed back as aDictionary<string, string>. Store one of those as a string of your own making.EndTimeUtcfalling between two fire times of the same day let the trigger go on firing until the daily window closed, andFinalFireTimeUtcreported that close even when it was a day past the end. (port of the daily half of #3458)NativeJobno longer deadlocks a child that writes more than a pipe buffer — both streams were redirected whether or notconsumeStreamsasked for them to be read, so with the defaults a chatty process blocked on its own write and the job's synchronous wait held a worker for ever. Nothing is redirected unless consumed. (port of the rc.1 fix)EnlistConnectioninside aTransactionScopetook aMicrosoft.Data.Sqliteconnection on trust, and SQLite cannot enlist, so every statement committed on the spot and a rolled-back scope left the schedule behind.EnlistTransaction(DbTransaction)still works there. (port of the beta.1 fix)now - MisfireThresholdwas a misfire toRAMJobStoreand to the ADO store's single-trigger path but not to its periodic sweep; the sweep says<=now and the acquisition predicate moved to>in step. (port of #3462)"3,14"read as314from the floating-point accessors whileGetIntthrew. (port of the beta.1 fix)GetDoubleandGetFloatthrow aFormatExceptionfor such a string where they used to answer a number a hundred times too large.[matches literally on SQL Server — T-SQL reads[as a character class inLIKE; it is escaped on that dialect only, because the standard forbids escaping a non-wildcard elsewhere. (port of the rc.1 fix)[matches the groups it names rather than the character class T-SQL read it as, so it can list, pause, resume or delete a different set than on 3.20.DirectoryScanJobstores its previous scan as something a job store can write — it kept aList<FileInfo>under[PersistJobDataAfterExecution], which System.Text.Json cannot write, so its first firing on such a store failed to persist. A legacy list already in a running scheduler is still read. (port of the rc.1 fix)DirectoryScanJobruns at all on 3.20 — it read its optional job-data keys withGetString, which throws for a key that is not there, so a job configured without a directory provider or listener name failed on every firing withKeyNotFoundException. Found while porting the previous item; the optional keys are asked for rather than read.SelectSchedulerStateRecordsbinds its parameters in statement order — only a provider withBindByNameoff could ever have noticed. (port of the alpha.3 fix)Public API
Unchanged. No signature was added, altered or removed, and the
PublicApiTestbaselines did not move.Upgrading
A drop-in upgrade from 3.20.0: no schema change, no configuration change, no migration script. Read the Behavior change worth noting bullets above — each is a case that used to be silently wrong and is now either correct or loud.
About the 4.0 line
Quartz.NET 4.0 was released on 2026-09-03. It targets
net10.0only; 3.x remains the line fornetstandard2.0and .NET Framework, and fixes that apply to both keep landing on both, which is what most of this release is. The migration guide is the map if you are considering the move.Full changes: quartznet/quartznet@v3.20.0...v3.20.1
dotnet/sdk (dotnet-sdk)
v10.0.401Compare Source
react/react (react)
v19.3.0Compare Source
react/react (react-dom)
v19.3.0Compare Source
vitejs/vite (vite)
v8.3.0Compare Source
Features
Bug Fixes
node_modulespath segments as dependencies (fix #17467) (#23437) (ef0dc17)Performance Improvements
Configuration
📅 Schedule: (UTC)
* 0-6 * * 2)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.