Skip to content

Update dependencies and build tooling - #370

Merged
niemyjski merged 9 commits into
mainfrom
feature/update-dependencies
Oct 6, 2026
Merged

niemyjski merged 9 commits into
mainfrom
feature/update-dependencies

Conversation

@niemyjski

@niemyjski niemyjski commented Jul 31, 2026 •

Copy link
Copy Markdown
Member

Refresh the build tooling, logging and MessagePack integrations, test packages, and sample dependencies. Client behavior and the existing publishing steps are unchanged; the settings/configuration-test changes, devcontainer changes, and three unrelated client-project package upgrades have been removed.

Validation: all six CI builds and CLA/Dependabot checks passed; 310 local tests passed (18 existing skips); nine samples built; 12 packages packed; local smoke checks passed; application dependency audits clean. One reviewer approval is still required.

Security caveat: the original Windows publishing tool is retained as requested. Its latest release, gpr 0.1.294, still bundles dependencies with five reported advisories. This publishing-tool risk remains unresolved. Windows desktop and legacy web sample runtimes, real AWS deployment, and external feed publishing were not exercised locally.

Verification and implementation details

Scope and compatibility

  • Checked current stable NuGet versions on October 5, 2026. Updated .NET SDK/SourceLink to 10.0.401, MinVer to 8.0.0, MessagePack to 3.1.11, NLog to 6.2.1, log4net to 3.5.0, and the test/sample packages to current compatible stable releases.
  • MessagePack 3.1.11 includes the LZ4 integer-overflow fix and the earlier regex denial-of-service fix.
  • Keep Exceptionless.csproj, Exceptionless.Extensions.Hosting.csproj, and Exceptionless.Extensions.Logging.csproj byte-for-byte identical to main: no advisories were reported for their restored dependency versions. Keep RandomData 1.2.2 in the test harness for its .NET Framework target.
  • xunit.v3.mtp-off preserves the existing VSTest workflow. The assembly-level parallelization attribute is updated for xUnit v4 while still disabling parallel tests. No configuration-test behavior changes remain.
  • GitHub Actions use the current supported major aliases, actions/checkout@v7 and actions/setup-dotnet@v6. Checkout no longer persists credentials; workflow token permissions are explicit. Both Windows Publish steps and the gpr installation step match main exactly.
  • MinVer 7 and 8 produced the same version at the same Git revision. All client assemblies built with zero warnings/errors; all 12 packages packed. Existing package-readme notices remain.
  • All hosted checks are green at c31015ee051c98b4b1254279b5699e3930b949ef, including the restored Windows CI-publishing step. Publishing logs reported duplicate versions already present on GitHub Packages and Feedz, not authentication failures. No release-tag publish was triggered.

Security verification

  • NuGet vulnerable/deprecated scans covered all 15 Windows-solution projects and all nine SDK-style sample graphs, including transitive packages: no findings. Desktop project evaluation requires EnableWindowsTargeting=true in the environment on macOS.
  • Recursive OSV scanning covered 28 manifests, including the legacy MVC packages.config: no findings. OSV also checked the resolved Windows Forms/WPF sample graphs and the actual MinVer 8 CLI dependency graphs: no findings.
  • NuGet repository signatures verified for all 20 upgraded direct package references and the MinVer CLI tool.
  • Separately scanned the actual gpr 0.1.294 tool dependency graph. Reported advisories affect Newtonsoft.Json 9.0.1 (CVE-2024-21907), NuGet.Common 5.6.0 (CVE-2023-29337), NuGet.Packaging 5.6.0 (CVE-2024-0057), System.Net.Http 4.3.0 (CVE-2018-8292), and System.Text.RegularExpressions 4.3.0 (CVE-2019-0820). This is an advisory inventory, not proof that every advisory is exploitable in the publishing path; runtime-provided assemblies can affect applicability.

Dogfooding

  • Built all nine SDK-style samples: ASP.NET Core, Blazor, console, hosting, Lambda, Lambda ASP.NET Core, Web API, Windows Forms, and WPF.
  • Console/NLog: started the actual sample, created an event, flushed the queue, and quit cleanly.
  • ASP.NET Core/hosting/local Lambda web: started actual samples, exercised missing routes and deliberate exception routes, verified expected 404/500 responses and ASP.NET Core Problem Details, then shut down. A loopback-only mock receiver accepted 40 events covering log, error, usage, and not-found types; no external service was used for these events.
  • Temporary smoke harness: MessagePack 3.1.11 rejected the publisher advisory's malformed LZ4 payload without a process crash; captured four NLog/log4net log/exception events; round-tripped Lambda JSON input and handler output; flushed Lambda events; and exercised API Gateway request marshalling/404 routing.
  • Blazor browser: home loaded, the counter advanced to 1 through its caught-exception path, and all five weather rows loaded. This proves local UI behavior, not backend delivery.
  • The three legacy MVC/Web/WCF samples require Windows/Visual Studio WebApplication targets/developer packs unavailable on this Mac. Desktop samples were compiled, not run.

Reproduction

dotnet restore Exceptionless.Net.NonWindows.slnx
dotnet test Exceptionless.Net.NonWindows.slnx -c Release --disable-build-servers -m:1
dotnet restore Exceptionless.Net.Windows.slnx -p:EnableWindowsTargeting=true
dotnet build Exceptionless.Net.Windows.slnx -c Release --no-restore -p:EnableWindowsTargeting=true --disable-build-servers -m:1
dotnet pack Exceptionless.Net.Windows.slnx -c Release --no-build --no-restore -p:EnableWindowsTargeting=true -o artifacts
EnableWindowsTargeting=true dotnet list Exceptionless.Net.Windows.slnx package --vulnerable --include-transitive --no-restore
EnableWindowsTargeting=true dotnet list Exceptionless.Net.Windows.slnx package --deprecated --include-transitive --no-restore
osv-scanner scan source -r .

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4d2a4383cd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/build-windows.yml Outdated
Copilot AI lite review requested due to automatic review settings September 3, 2026 03:12
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T02:45:39.604406Z c31015e New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The changes are primarily dependency/tooling updates with a single minor CI script robustness nit noted in review comments.

Pull request overview

This PR refreshes NuGet dependencies and build/developer tooling across the Exceptionless .NET repo (tests, platform integrations, samples, CI, and devcontainer) while keeping target frameworks and production code behavior unchanged.

Changes:

  • Updates test tooling to xUnit v4 / MTP-off + Microsoft.NET.Test.Sdk 18.9.0, and adjusts assembly-level parallelism configuration.
  • Bumps key integration dependencies (e.g., NLog, log4net, MessagePack, Microsoft.Extensions packages, AWS Lambda/AWS SDK sample refs).
  • Modernizes CI/workflow tooling (checkout/setup-dotnet majors, MinVer CLI), adds Dependabot coverage for additional ecosystems, and refreshes the devcontainer image/lock.
File summaries
File Description
test/Exceptionless.Tests/Properties/AssemblyInfo.cs Updates assembly-level xUnit parallelism control for xUnit v4.
test/Exceptionless.Tests/Exceptionless.Tests.csproj Bumps test SDK and switches to xUnit v4 MTP-off + VS adapter v4.
test/Exceptionless.TestHarness/Exceptionless.TestHarness.csproj Updates xUnit assertions package version.
test/Exceptionless.MessagePack.Tests/Exceptionless.MessagePack.Tests.csproj Bumps test SDK and switches to xUnit v4 MTP-off + VS adapter v4.
src/Platforms/Exceptionless.NLog/Exceptionless.NLog.csproj Updates NLog dependency version.
src/Platforms/Exceptionless.MessagePack/Exceptionless.MessagePack.csproj Updates MessagePack dependency version.
src/Platforms/Exceptionless.Log4net/Exceptionless.Log4net.csproj Updates log4net dependency version.
src/Platforms/Exceptionless.Extensions.Logging/Exceptionless.Extensions.Logging.csproj Updates Microsoft.Extensions.Logging versions per target framework.
src/Platforms/Exceptionless.Extensions.Hosting/Exceptionless.Extensions.Hosting.csproj Updates Microsoft.Extensions.Hosting.Abstractions versions per target framework.
src/Exceptionless/Exceptionless.csproj Updates core package references (Configuration.Abstractions, Reflection.Metadata).
samples/Exceptionless.SampleLambdaAspNetCore/Exceptionless.SampleLambdaAspNetCore.csproj Updates AWS Setup + Lambda ASP.NET Core Server dependencies.
samples/Exceptionless.SampleLambda/Exceptionless.SampleLambda.csproj Updates Lambda core + STJ serializer dependency versions.
samples/Exceptionless.SampleBlazorWebAssemblyApp/Exceptionless.SampleBlazorWebAssemblyApp.csproj Updates Blazor WebAssembly package versions.
global.json Updates pinned .NET SDK feature band version.
build/common.props Updates SourceLink package version.
.github/workflows/build-windows.yml Updates action majors, MinVer CLI, publish logic, and workflow permissions.
.github/workflows/build-osx.yml Updates action majors, MinVer CLI, and checkout credential persistence behavior.
.github/workflows/build-linux.yml Updates action majors, MinVer CLI, and checkout credential persistence behavior.
.github/dependabot.yml Expands Dependabot coverage to Actions, Dev Containers, and dotnet-sdk.
.devcontainer/devcontainer.json Updates devcontainer base image and adds dotnet feature configuration.
.devcontainer/devcontainer-lock.json Adds devcontainer feature lock for reproducibility.
Review details
  • Files reviewed: 21/21 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/build-windows.yml
@niemyjski niemyjski changed the title chore: update dependencies and build tooling Update dependencies and fix concurrent settings initialization Sep 22, 2026
@niemyjski niemyjski changed the title Update dependencies and fix concurrent settings initialization Update dependencies and build tooling Oct 6, 2026
@niemyjski
niemyjski merged commit 2054b80 into main Oct 6, 2026
8 checks passed
@niemyjski
niemyjski deleted the feature/update-dependencies branch October 6, 2026 03:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants