Skip to content

Update dependencies and fix concurrent settings initialization - #370

Open
niemyjski wants to merge 7 commits into
mainfrom
feature/update-dependencies
Open

niemyjski wants to merge 7 commits into
mainfrom
feature/update-dependencies

Conversation

@niemyjski

@niemyjski niemyjski commented Jul 31, 2026 •

Copy link
Copy Markdown
Member

Refresh client, sample, and build dependencies, and replace the vulnerable gpr publishing tool with native NuGet publishing. Fix a settings-initialization race that could throw during concurrent logging by replacing two dependent cache writes with one atomic lookup and removing the unused cache. Public APIs and target frameworks are preserved.

Validation: six Linux/macOS/Windows CI builds passed; September 21 review passed 312 tests (18 existing skips), behavior comparisons, and refreshed NuGet/OSV security audits.

Compatibility: dependency minimums increase, and log4net 3.4 changes some appender timeout defaults. Legacy Windows sample builds/runtime, desktop interaction, and hosted AWS invocation remain unverified locally. One reviewer approval is required before merge.

Verification and implementation details

Changes and rationale

  • Update .NET SDK to 10.0.400, SourceLink to 10.0.400, core Configuration/Metadata packages to 10.0.11, MessagePack to 3.1.8, NLog to 6.2.0, log4net to 3.4.0, and AWS/Blazor sample dependencies. Hosting/logging integrations retain their matching Microsoft.Extensions 8/9/10 lines; net472 retains compatible RandomData 1.2.2.
  • Update test SDK to 18.9.0 and xUnit to 4.0.0. The official xunit.v3.mtp-off package preserves VSTest and existing dotnet test commands. The new parallelization attribute preserves serial execution.
  • Use actions/checkout@v7 and actions/setup-dotnet@v6, restrict workflow permissions, and disable persisted checkout credentials. Add Dependabot coverage for Actions, Dev Container Features, and the SDK. Action major tags are intentionally mutable.
  • Preserve GitHub publishing as best effort, required Feedz publishing, and tag-triggered NuGet releases. Both publish loops preserve package paths containing whitespace or wildcard characters. Removing gpr removes its embedded vulnerable Newtonsoft.Json/NuGet dependencies.
  • Use the official versioned .NET devcontainer image and a locked Feature digest. global.json remains the SDK version owner.
  • The removed settings cache never stored values. Its reads and invalidation loop were ineffective; removing them reduces production code by 35 lines. Atomic GetOrAdd preserves the prefix comparer without adding locks or changing filtering rules. Regression coverage exercises concurrent cold starts and subsequent settings updates.

Evidence

Reviewed head: f9ddd3de39a7a8515d66f2df7fa7c39cb323fde6; base: 5eb567a599c1a6fd9a704d79dda1418488a88526.

  • September 21: Release suite passed 312 tests with 18 existing skips using SDK 10.0.401, selected by the existing roll-forward policy. A temporary deterministic comparison against the base settings implementation matched 560,000 results across null/case/wildcard inputs, add/update/remove/clear/apply operations, and change notifications. No further source edits were needed.
  • September 21: refreshed Windows-target solution restore plus direct/transitive NuGet vulnerability and deprecation checks found no affected packages. All nine SDK-style sample vulnerability audits passed. OSV found no issues across 28 manifests, including legacy MVC packages.config.
  • Same-head hosted CI, September 2–3: all six push/PR builds and CLA passed. Windows push ran 613 tests with 36 existing skips across net10.0/net472, packaged all 12 clients, and published to both CI feeds. Windows PR passed independently. Both review threads are resolved.
  • Earlier validation on this change: all nine SDK-style samples built; console, ASP.NET Core/Lambda endpoints, logging adapters, and Lambda serialization smoke checks passed. Blazor served HTML/framework assets; interactive browser execution was not covered. The devcontainer built with its frozen lockfile and booted successfully. Workflow lint and mocked publishing-path checks passed. Nine refreshed direct NuGet package archives passed hash/signature verification.
  • The 328 original test identities/outcomes were retained; two passing event-filter regression cases were added. No tests were disabled by this PR. Framework targets and public signatures are unchanged.

Core reproduction commands:

dotnet test Exceptionless.Net.NonWindows.slnx -c Release
dotnet restore Exceptionless.Net.Windows.slnx -p:OS=Windows_NT -p:NuGetAuditMode=all --force-evaluate
OS=Windows_NT dotnet list Exceptionless.Net.Windows.slnx package --vulnerable --include-transitive --no-restore
OS=Windows_NT dotnet list Exceptionless.Net.Windows.slnx package --deprecated --include-transitive --no-restore
osv-scanner scan source -r .

On Windows, build and test Exceptionless.Net.Windows.slnx natively. Cross-target restore/build on macOS does not prove Windows runtime behavior. NuGet/OSV checks are not a container OS vulnerability scan.

Upstream compatibility references

log4net 3.4.0 and timeout changes, NLog 6.2, xUnit 4.0 migration, Test SDK 18.9, AWS Lambda, and AWS SDK.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4d2a4383cd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/build-windows.yml
Copilot AI lite review requested due to automatic review settings September 3, 2026 03:12
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-03T03:23:48.114874Z f9ddd3d New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The changes are primarily dependency/tooling updates with a single minor CI script robustness nit noted in review comments.

Pull request overview

This PR refreshes NuGet dependencies and build/developer tooling across the Exceptionless .NET repo (tests, platform integrations, samples, CI, and devcontainer) while keeping target frameworks and production code behavior unchanged.

Changes:

  • Updates test tooling to xUnit v4 / MTP-off + Microsoft.NET.Test.Sdk 18.9.0, and adjusts assembly-level parallelism configuration.
  • Bumps key integration dependencies (e.g., NLog, log4net, MessagePack, Microsoft.Extensions packages, AWS Lambda/AWS SDK sample refs).
  • Modernizes CI/workflow tooling (checkout/setup-dotnet majors, MinVer CLI), adds Dependabot coverage for additional ecosystems, and refreshes the devcontainer image/lock.
File summaries
File Description
test/Exceptionless.Tests/Properties/AssemblyInfo.cs Updates assembly-level xUnit parallelism control for xUnit v4.
test/Exceptionless.Tests/Exceptionless.Tests.csproj Bumps test SDK and switches to xUnit v4 MTP-off + VS adapter v4.
test/Exceptionless.TestHarness/Exceptionless.TestHarness.csproj Updates xUnit assertions package version.
test/Exceptionless.MessagePack.Tests/Exceptionless.MessagePack.Tests.csproj Bumps test SDK and switches to xUnit v4 MTP-off + VS adapter v4.
src/Platforms/Exceptionless.NLog/Exceptionless.NLog.csproj Updates NLog dependency version.
src/Platforms/Exceptionless.MessagePack/Exceptionless.MessagePack.csproj Updates MessagePack dependency version.
src/Platforms/Exceptionless.Log4net/Exceptionless.Log4net.csproj Updates log4net dependency version.
src/Platforms/Exceptionless.Extensions.Logging/Exceptionless.Extensions.Logging.csproj Updates Microsoft.Extensions.Logging versions per target framework.
src/Platforms/Exceptionless.Extensions.Hosting/Exceptionless.Extensions.Hosting.csproj Updates Microsoft.Extensions.Hosting.Abstractions versions per target framework.
src/Exceptionless/Exceptionless.csproj Updates core package references (Configuration.Abstractions, Reflection.Metadata).
samples/Exceptionless.SampleLambdaAspNetCore/Exceptionless.SampleLambdaAspNetCore.csproj Updates AWS Setup + Lambda ASP.NET Core Server dependencies.
samples/Exceptionless.SampleLambda/Exceptionless.SampleLambda.csproj Updates Lambda core + STJ serializer dependency versions.
samples/Exceptionless.SampleBlazorWebAssemblyApp/Exceptionless.SampleBlazorWebAssemblyApp.csproj Updates Blazor WebAssembly package versions.
global.json Updates pinned .NET SDK feature band version.
build/common.props Updates SourceLink package version.
.github/workflows/build-windows.yml Updates action majors, MinVer CLI, publish logic, and workflow permissions.
.github/workflows/build-osx.yml Updates action majors, MinVer CLI, and checkout credential persistence behavior.
.github/workflows/build-linux.yml Updates action majors, MinVer CLI, and checkout credential persistence behavior.
.github/dependabot.yml Expands Dependabot coverage to Actions, Dev Containers, and dotnet-sdk.
.devcontainer/devcontainer.json Updates devcontainer base image and adds dotnet feature configuration.
.devcontainer/devcontainer-lock.json Adds devcontainer feature lock for reproducibility.
Review details
  • Files reviewed: 21/21 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/build-windows.yml Outdated
@niemyjski niemyjski changed the title chore: update dependencies and build tooling Update dependencies and fix concurrent settings initialization Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants