Skip to content

deps: Bump the dotnet group with 7 updates - #94

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/dot-config/dotnet-574f89f68e
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/dot-config/dotnet-574f89f68e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Updated Aspire.Hosting from 13.5.4 to 13.6.1.

Release notes

Sourced from Aspire.Hosting's releases.

13.6.1

What's New in Aspire 13.6.1

Patch release for Aspire 13.6 that reduces dashboard CPU usage during sustained metric ingestion, restores scrolling in the Metrics tree, improves dashboard navigation, fixes container exec watch failures, and ensures session-scoped containers are cleaned up when stopping .NET AppHosts on Windows.

🐛 Fixes

  • 📊 Dashboard CPU usage could increase during long-running metric ingestion — Metric retention repeatedly scanned retained history on every insertion, causing steadily increasing CPU usage even with a fixed workload. Cleanup now skips dimensions below capacity and removes only the oldest surplus points when needed. Existing retention limits and exemplar behavior are unchanged, and no configuration changes are required. Regression introduced in 13.6. Fixes #​20725. (#​20747, backport of #​20736, @​JamesNK)

  • 📈 The Metrics tree could not be scrolled — The meter and instrument tree now scrolls when it exceeds the viewport, allowing you to reach and select instruments below the fold. Regression introduced in 13.6. Fixes #​20728. (#​20762, backport of #​20758, @​heyysiri)

  • 🧭 Dashboard navigation could fail after a browser disconnect — Pending page-state updates now persist session state before navigating and skip navigation when the browser has disconnected, avoiding an unhandled navigation failure. The navigation rail's overflow button also has consistent sizing, icon alignment, and hover styling in expanded and collapsed layouts and both light and dark themes. (#​20545, backport of #​20527, @​JamesNK)

  • 🖥️ Container exec watches could terminate shortly after AppHost startup — A stalled DCP watch connection could produce a critical Watch task over Kubernetes ContainerExec resources terminated unexpectedly error and stop subsequent terminal state and log updates from being observed. Watch connection attempts now retry after timeouts, and periodic restarts correctly recreate connections without swallowing unrelated cancellation. Regression introduced in 13.6.0. (#​20664, backport of #​20466, @​radical)

  • 🪟 Session-scoped containers could remain running after stopping a .NET AppHost on Windows — AppHosts launched through dotnet run or dotnet watch now allow DCP to finish resource cleanup during shutdown, including existing Ctrl+C and aspire stop flows. Persistent resources remain unaffected, while direct .NET launches and TypeScript/polyglot AppHosts retain their existing process protection. Fixes #​20495. (#​20514, backport of #​20494, @​danegsta)


Full Changelog: v13.6.0...v13.6.1

Full commit: 3751e615ad660621f2a7aa4c390ef48e08a0eed8

13.6.0

Aspire 13.6.0

Aspire 13.6 brings persistent application history, a refreshed and more interactive dashboard, first-party Java and Rust hosting, and new Azure deployment options. Coordinated .NET builds, portable volume paths, sharper CLI workflows, and more capable editor tooling make it easier to build, debug, and deploy applications across languages.

Highlights

  • 🗃️ Persistent, refreshed dashboard — SQLite-backed telemetry and resource snapshots let you revisit up to ten application runs, with read-only access to completed runs and default retention limits of 100,000 console log messages, structured logs, and traces each. The dashboard now ships as Native AOT and adopts Fluent UI v5 with a collapsible navigation rail.
  • 🖥️ AppHost-owned terminals and database REPLs — Experimental terminal APIs let AppHosts create interactive sessions in a dashboard dock, dialog, or separate window. Opt-in WithRepl() commands open bundled clients for PostgreSQL, MySQL, MongoDB, SQL Server, Redis, and Valkey, while aspire terminal ps and aspire terminal tape play support discovery and repeatable terminal interactions.
  • 🌐 First-party Java and Rust hosting — New Aspire.Hosting.Java and Aspire.Hosting.Rust packages bring Maven, Gradle, Spring Boot, Quarkus, and Cargo applications into the app model, with generated container builds and VS Code debugging. These integrations build on work that originated in the Aspire Community Toolkit.
  • 🛠️ More flexible AppHosts — The prerelease Aspire.Hosting.Dotnet integration coordinates compatible projects into shared restore and build groups and supports .NET SDK container publishing. Portable volume-path environment variables work across local execution and deployment, while TypeScript AppHosts gain standard appsettings.json configuration and Deno runtime support.
  • ⌨️ Sharper CLI workflows — Select launch profiles with aspire run and aspire start, update repository-local CLI manifests with aspire update, create file-based C# AppHosts with aspire init --language csharp --file-based, and export TypeScript API data with aspire sdk export. Terminal commands no longer need a feature flag, Linux certificate trust includes Firefox NSS databases, and aspire stop --force --volumes adds explicit cleanup of Aspire-owned volumes.
  • 💻 More capable VS Code tooling — Coding agents can start and stop AppHosts through the extension, and the Aspire pane exposes deploy, publish, and pipeline actions. Multi-root discovery, worktree-scoped lifecycle operations, preserved launch arguments, clearer debug logs, and missing-debugger guidance make complex workspaces more predictable.
  • ☁️ New Azure options in preview — Azure Connector Namespace models external-service connections and managed MCP server configurations. Azure Container Apps Sandboxes adds isolated sandbox deployments with configurable resource tiers and lifecycle policies, while Azure Container Apps Express offers a simplified environment option for rapid provisioning.
  • ☸️ More expressive, reliable deployments — Experimental Azure Provisioning SDK proxies let polyglot AppHosts customize infrastructure. Deployment state is isolated under ASPIRE_HOME, Kubernetes preserves inherited hostnames and embedded parameter values, and AKS gains persistent-volume provisioning and more reliable cleanup.
  • 🔌 Expanded integrations — Experimental Deno hosting and MongoDB replica sets join Foundry Toolboxes, remote Foundry Local endpoints, Blazor WebAssembly debugging, and configurable Dev Tunnel expiration. Azure Cosmos DB and AI Inference client integrations gain health checks, and the vNext Cosmos DB emulator sends its own telemetry to the dashboard.

⚠️ Breaking changes

Notable changes include automatic TLS for local MongoDB servers when a certificate is available, the Linux-based vNext Cosmos DB emulator becoming the default, new Azure Front Door origin names that can require cleanup of existing origins, portable connection-string environment-variable aliases on stricter deployment targets, and experimental terminal types moving from Aspire.Hosting.Terminals to Aspire.Hosting.ApplicationModel.

See the full list and migration guidance in the Aspire 13.6 breaking changes.

📖 Learn more

For complete details, examples, migration guidance, and everything new in this release, read What's new in Aspire 13.6.

Thank you to all the community contributors who helped make Aspire 13.6 possible! 💜


Full Changelog: v13.5.4...v13.6.0

Full commit: 56f3e9c0d216c0c7069dabb49dd0464e4827744f

Commits viewable in compare view.

Updated Azure.Security.KeyVault.Secrets from 4.11.1 to 4.11.2.

Release notes

Sourced from Azure.Security.KeyVault.Secrets's releases.

4.11.2

4.11.2 (2026-10-02)

Bugs Fixed

  • Fixed handling of claims challenges when the authentication challenge cache is empty or cleared while a request is in flight.
  • Fixed an issue in the challenge-based authentication policy where a cached authentication challenge accepted with challenge resource verification disabled could be reused by a separate default-strict client without revalidating the challenge resource.
  • Improved authentication challenge resource validation.

Commits viewable in compare view.

Updated HotChocolate.AspNetCore from 16.6.6 to 16.6.8.

Release notes

Sourced from HotChocolate.AspNetCore's releases.

16.6.8

What's Changed

Full Changelog: ChilliCream/graphql-platform@16.6.7...16.6.8

16.6.7

What's Changed

Full Changelog: ChilliCream/graphql-platform@16.6.6...16.6.7

Commits viewable in compare view.

Updated HotChocolate.Subscriptions.InMemory from 16.6.6 to 16.6.8.

Release notes

Sourced from HotChocolate.Subscriptions.InMemory's releases.

16.6.8

What's Changed

Full Changelog: ChilliCream/graphql-platform@16.6.7...16.6.8

16.6.7

What's Changed

Full Changelog: ChilliCream/graphql-platform@16.6.6...16.6.7

Commits viewable in compare view.

Updated Markdig from 1.3.2 to 1.4.0.

Release notes

Sourced from Markdig's releases.

1.4.0

Changes

✨ New Features

  • Add strict GFM pipe table parsing mode (14cd25c7)

🐛 Bug Fixes

  • Fix heading auto-link hijacking nested link labels (#​668) (PR #​949) by @​dualfroz
  • Fix: keep trailing content out of an unmatched emphasis closer (#​743) (PR #​950) by @​dualfroz
  • Fix indent on first list item (#​482) (PR #​953) by @​boxofyellow
  • Add Normalization Support for PipeTables (GFM) (PR #​954) by @​boxofyellow
  • Fix partially empty pipe table separator regression (PR #​955) by @​vicancy
  • Reject emoji-parsing if the slice ends with ** (PR #​947) by @​bstordrup
  • Fix strict GFM tables against native cmark-gfm (86866b91)

🚀 Enhancements

  • Update 3rd party extensions (PR #​945) by @​Kryptos-FR

🏭 Tests

  • Fix tests warnings (96b024c2)

📦 Dependencies

  • Bump deps (c6b186b4)

🧰 Misc

  • Use NuGet Trusted Publishing via dotnet-releaser (56e9c238)

Full Changelog: 1.3.2...1.4.0

Published with dotnet-releaser

Commits viewable in compare view.

Updated Spectre.Console.Cli from 0.55.0 to 0.57.2.

Release notes

Sourced from Spectre.Console.Cli's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated tap.studio.cli from 0.7.7 to 0.7.8.

Release notes

Sourced from tap.studio.cli's releases.

0.7.8

Downloads

Tap Studio — the desktop workbench.

Platform File
macOS (Apple silicon) Tap.Studio_0.7.8_aarch64.dmg
Windows (installer) Tap.Studio_0.7.8_x64-setup.exe
Windows (MSI) Tap.Studio_0.7.8_x64_en-US.msi
Linux (Debian/Ubuntu) Tap.Studio_0.7.8_amd64.deb

Tap Tunnels — the tap inspector CLI.

Platform File
macOS (Apple silicon) tap-0.7.8-osx-arm64.tar.gz
macOS (Intel) tap-0.7.8-osx-x64.tar.gz
Linux (x64) tap-0.7.8-linux-x64.tar.gz
Linux (arm64) tap-0.7.8-linux-arm64.tar.gz
Windows dotnet tool install -g Tap

Checksums for the CLI archives are in SHA256SUMS.


A small Studio release: a place to manage workspaces, two fixes, and a round of dependency
updates.

Manage workspaces

The workspace switcher gains a Manage workspaces… entry at the bottom. It opens a
Workspaces tab listing every workspace Studio knows about:

Column
Name The manifest name, with Active and Missing badges
Path The full folder path
Git Branch and origin remote, linked to the repository in the browser

Each row can be opened (switch to it), edited (switch, then open its manifest), or
removed. Removing only forgets the entry — the folder and its files stay on disk, and you
can add it back any time. The active workspace cannot be removed; switch away first.

The tab stays open across a workspace switch, so it works as a hub for hopping between
projects. When an Aspire AppHost pins the workspace, the entry is hidden and the tab's
actions are disabled, as the switcher itself already is.

Fixes

... (truncated)

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Aspire.Hosting from 13.5.4 to 13.6.1
Bumps Azure.Security.KeyVault.Secrets from 4.11.1 to 4.11.2
Bumps HotChocolate.AspNetCore from 16.6.6 to 16.6.8
Bumps HotChocolate.Subscriptions.InMemory from 16.6.6 to 16.6.8
Bumps Markdig from 1.3.2 to 1.4.0
Bumps Spectre.Console.Cli from 0.55.0 to 0.57.2
Bumps tap.studio.cli from 0.7.7 to 0.7.8

---
updated-dependencies:
- dependency-name: Aspire.Hosting
  dependency-version: 13.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet
- dependency-name: Azure.Security.KeyVault.Secrets
  dependency-version: 4.11.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet
- dependency-name: HotChocolate.AspNetCore
  dependency-version: 16.6.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet
- dependency-name: HotChocolate.Subscriptions.InMemory
  dependency-version: 16.6.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet
- dependency-name: Markdig
  dependency-version: 1.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet
- dependency-name: Spectre.Console.Cli
  dependency-version: 0.57.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet
- dependency-name: tap.studio.cli
  dependency-version: 0.7.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Oct 10, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

0 participants