Repository navigation
Update dependencies and build tooling - #370
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4d2a4383cd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
🟢 Approval recommended
The changes are primarily dependency/tooling updates with a single minor CI script robustness nit noted in review comments.
Pull request overview
This PR refreshes NuGet dependencies and build/developer tooling across the Exceptionless .NET repo (tests, platform integrations, samples, CI, and devcontainer) while keeping target frameworks and production code behavior unchanged.
Changes:
- Updates test tooling to xUnit v4 / MTP-off + Microsoft.NET.Test.Sdk 18.9.0, and adjusts assembly-level parallelism configuration.
- Bumps key integration dependencies (e.g., NLog, log4net, MessagePack, Microsoft.Extensions packages, AWS Lambda/AWS SDK sample refs).
- Modernizes CI/workflow tooling (checkout/setup-dotnet majors, MinVer CLI), adds Dependabot coverage for additional ecosystems, and refreshes the devcontainer image/lock.
File summaries
| File | Description |
|---|---|
| test/Exceptionless.Tests/Properties/AssemblyInfo.cs | Updates assembly-level xUnit parallelism control for xUnit v4. |
| test/Exceptionless.Tests/Exceptionless.Tests.csproj | Bumps test SDK and switches to xUnit v4 MTP-off + VS adapter v4. |
| test/Exceptionless.TestHarness/Exceptionless.TestHarness.csproj | Updates xUnit assertions package version. |
| test/Exceptionless.MessagePack.Tests/Exceptionless.MessagePack.Tests.csproj | Bumps test SDK and switches to xUnit v4 MTP-off + VS adapter v4. |
| src/Platforms/Exceptionless.NLog/Exceptionless.NLog.csproj | Updates NLog dependency version. |
| src/Platforms/Exceptionless.MessagePack/Exceptionless.MessagePack.csproj | Updates MessagePack dependency version. |
| src/Platforms/Exceptionless.Log4net/Exceptionless.Log4net.csproj | Updates log4net dependency version. |
| src/Platforms/Exceptionless.Extensions.Logging/Exceptionless.Extensions.Logging.csproj | Updates Microsoft.Extensions.Logging versions per target framework. |
| src/Platforms/Exceptionless.Extensions.Hosting/Exceptionless.Extensions.Hosting.csproj | Updates Microsoft.Extensions.Hosting.Abstractions versions per target framework. |
| src/Exceptionless/Exceptionless.csproj | Updates core package references (Configuration.Abstractions, Reflection.Metadata). |
| samples/Exceptionless.SampleLambdaAspNetCore/Exceptionless.SampleLambdaAspNetCore.csproj | Updates AWS Setup + Lambda ASP.NET Core Server dependencies. |
| samples/Exceptionless.SampleLambda/Exceptionless.SampleLambda.csproj | Updates Lambda core + STJ serializer dependency versions. |
| samples/Exceptionless.SampleBlazorWebAssemblyApp/Exceptionless.SampleBlazorWebAssemblyApp.csproj | Updates Blazor WebAssembly package versions. |
| global.json | Updates pinned .NET SDK feature band version. |
| build/common.props | Updates SourceLink package version. |
| .github/workflows/build-windows.yml | Updates action majors, MinVer CLI, publish logic, and workflow permissions. |
| .github/workflows/build-osx.yml | Updates action majors, MinVer CLI, and checkout credential persistence behavior. |
| .github/workflows/build-linux.yml | Updates action majors, MinVer CLI, and checkout credential persistence behavior. |
| .github/dependabot.yml | Expands Dependabot coverage to Actions, Dev Containers, and dotnet-sdk. |
| .devcontainer/devcontainer.json | Updates devcontainer base image and adds dotnet feature configuration. |
| .devcontainer/devcontainer-lock.json | Adds devcontainer feature lock for reproducibility. |
Review details
- Files reviewed: 21/21 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Refresh the build tooling, logging and MessagePack integrations, test packages, and sample dependencies. Client behavior and the existing publishing steps are unchanged; the settings/configuration-test changes, devcontainer changes, and three unrelated client-project package upgrades have been removed.
Validation: all six CI builds and CLA/Dependabot checks passed; 310 local tests passed (18 existing skips); nine samples built; 12 packages packed; local smoke checks passed; application dependency audits clean. One reviewer approval is still required.
Security caveat: the original Windows publishing tool is retained as requested. Its latest release,
gpr 0.1.294, still bundles dependencies with five reported advisories. This publishing-tool risk remains unresolved. Windows desktop and legacy web sample runtimes, real AWS deployment, and external feed publishing were not exercised locally.Verification and implementation details
Scope and compatibility
Exceptionless.csproj,Exceptionless.Extensions.Hosting.csproj, andExceptionless.Extensions.Logging.csprojbyte-for-byte identical tomain: no advisories were reported for their restored dependency versions. Keep RandomData 1.2.2 in the test harness for its .NET Framework target.xunit.v3.mtp-offpreserves the existing VSTest workflow. The assembly-level parallelization attribute is updated for xUnit v4 while still disabling parallel tests. No configuration-test behavior changes remain.actions/checkout@v7andactions/setup-dotnet@v6. Checkout no longer persists credentials; workflow token permissions are explicit. Both WindowsPublishsteps and thegprinstallation step matchmainexactly.c31015ee051c98b4b1254279b5699e3930b949ef, including the restored Windows CI-publishing step. Publishing logs reported duplicate versions already present on GitHub Packages and Feedz, not authentication failures. No release-tag publish was triggered.Security verification
EnableWindowsTargeting=truein the environment on macOS.packages.config: no findings. OSV also checked the resolved Windows Forms/WPF sample graphs and the actual MinVer 8 CLI dependency graphs: no findings.gpr 0.1.294tool dependency graph. Reported advisories affect Newtonsoft.Json 9.0.1 (CVE-2024-21907), NuGet.Common 5.6.0 (CVE-2023-29337), NuGet.Packaging 5.6.0 (CVE-2024-0057), System.Net.Http 4.3.0 (CVE-2018-8292), and System.Text.RegularExpressions 4.3.0 (CVE-2019-0820). This is an advisory inventory, not proof that every advisory is exploitable in the publishing path; runtime-provided assemblies can affect applicability.Dogfooding
Reproduction