Skip to content

Update packages - #34

Merged
matthewdevenny merged 2 commits into
mainfrom
matt/package-updates
Jun 30, 2026
Merged

matthewdevenny merged 2 commits into
mainfrom
matt/package-updates

Conversation

@matthewdevenny

@matthewdevenny matthewdevenny commented Jun 30, 2026 •

Copy link
Copy Markdown
Contributor

Maintenance pass to modernize the repo and refresh dependencies. The published libraries (CodeCargo.Nats.DistributedCache, CodeCargo.Nats.HybridCacheExtensions) continue to target net8.0;net10.0 — no consumer-facing target-framework change.

Dependencies → latest stable

Package(s) From To
Microsoft.Extensions.* (Caching.Abstractions, Logging(.Abstractions), Options, Caching.StackExchangeRedis) 10.0.1 10.0.9
Microsoft.Extensions.Caching.Hybrid 10.1.0 10.7.0
Microsoft.SourceLink.GitHub 8.0.0 10.0.300
NATS.Client.KeyValueStore / NATS.Net / NATS.Extensions.Microsoft.DependencyInjection 2.7.0 2.8.2
Aspire.Hosting.* + Aspire.AppHost.Sdk 13.1.0 13.4.6
Microsoft.NET.Test.Sdk 18.0.1 18.7.0
xunit.v3 (+ assert, extensibility.core) 3.2.1 3.2.2

NATS is on the latest stable; 3.0.0 is still preview-only. Moq and xunit.runner.visualstudio were already current.

Fixes a currently-red build: MessagePack 2.5.192 (transitive via Aspire 13.1.0) has published advisories (NU1902/NU1903), and CI builds with TreatWarningsAsErrors=true. Bumping Aspire to 13.4.6 pulls patched MessagePack 2.5.302 and clears it.

Aspire 13 AppHost migration

Aspire 13.0 is a project-format breaking change, so the AppHosts (util/NatsAppHost, util/RedisAppHost) were converted to the new SDK-style format:

  • <Project Sdk="Aspire.AppHost.Sdk/13.4.6"> (replaces the Microsoft.NET.Sdk base + <Sdk Name=…/> import)
  • dropped the explicit Aspire.Hosting.AppHost reference (the SDK now includes it)

Aspire 13 AppHosts are net10.0-only, so the projects that reference them — test/IntegrationTests (binds Projects.NatsAppHost at compile time), util/PerfTest, util/ReadmeExample — are now net10.0-only too. Libraries and test/UnitTests remain net8.0;net10.0.

Coverage note: integration tests now run on net10.0 only (previously net8.0+net10.0). Unit tests still cover both runtimes; the cache logic isn't runtime-version-specific.

Solution format → .slnx

  • Migrated NatsDistributedCache.sln → NatsDistributedCache.slnx (dotnet sln migrate) and removed the old .sln.
  • Updated the references that depend on the filename: the AppHost's runtime repo-root search (util/NatsAppHost/Program.cs) and the dev/{generate,verify}-snk.sh scripts.

Build reproducibility

  • Added linux-arm64 to the per-RID NuGet lock file set (dev/update-nuget-lockfiles.sh) — 9 new packages.linux-arm64.lock.json files for ARM Linux runners/containers.
  • Added a "Verify NuGet lock files are in sync" step to build.yml: reruns the regen script and fails on any *.lock.json drift, keeping all four RID copies honest on the existing x64 runner (regeneration is deterministic, so no false positives).

CI / tooling

  • dotnet-outdated-tool 4.6.9 → 4.8.1
  • actions/checkout v6 → v7; code-cargo/cargowall-action v1.2.0 → v1.3.0 (SHA-pinned)
  • CONTRIBUTING.md: build now requires the .NET 10 SDK (for the Aspire AppHosts); documented the new linux-arm64 lock file

Verification (local)

  • dotnet build -p TreatWarningsAsErrors=true — 0 warnings, 0 errors
  • dotnet format --verify-no-changes + BOM check — clean
  • Unit tests — 36 pass × net8.0 + net10.0
  • Integration tests (Docker/Aspire) — 58 pass × net10.0
  • Lock files regenerated for all 4 RIDs; locked-mode restore validated

🤖 Generated with Claude Code

Signed-off-by: Matthew DeVenny <matt@codecargo.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review this pull request because it exceeds the maximum number of lines (20,000). Try reducing the number of changed lines and requesting a review from Copilot again.

Signed-off-by: Matthew DeVenny <matt@codecargo.com>
@matthewdevenny
matthewdevenny marked this pull request as ready for review June 30, 2026 15:32

@mtmk mtmk left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@matthewdevenny
matthewdevenny merged commit ba30fd1 into main Jun 30, 2026
3 checks passed
@matthewdevenny
matthewdevenny deleted the matt/package-updates branch June 30, 2026 15:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants