chore(deps): upgrade Aspire to 13.5.4 and all NuGet packages to latest - #1396
Merged
Merged
Conversation
- Aspire.AppHost.Sdk + Aspire.Hosting.* 13.4.0 -> 13.5.4 (upgraded together; mixed 13.4/13.5 packages fail at runtime). Suppress ASPIRE010 - we run via `dotnet run` with NuGet-restored DCP/dashboard, not the Aspire CLI bundle. - .NET 10 platform packages 10.0.8 -> 10.0.12, EF Core 10.0.12, Npgsql EF 10.0.3, OpenTelemetry 1.19, Asp.Versioning 10.2, Scalar 2.17, QuestPDF 2026.9, Hangfire 1.8.25, MailKit/MimeKit 4.18, AWSSDK.S3 4.0.103, Testcontainers 4.15, SonarAnalyzer 10.34, and the rest to latest stable. - Majors: StackExchange.Redis 3.3.1 (same API as 2.13.17, new IO core, RESP3 by default), NSubstitute 6.2.0, xunit.runner.visualstudio 4.0.0 (still runs v2). - Security pins bumped within their lines: Microsoft.OpenApi 2.12.2 (stays 2.x), System.Security.Cryptography.Xml 10.0.12, SQLitePCLRaw.lib.e_sqlite3 3.53.3, MessagePack 2.5.305. - SonarAnalyzer S8969 (new): removed 157 redundant null-forgiving operators; compile-time only. Hangfire basic-auth filter uses header.ToString() where Sonar and the compiler disagreed. - S8949 (new): TenantProvisioningService passes CancellationToken.None explicitly into the Hangfire job expression. - AV0029/AV0030 (Asp.Versioning 10.2 advisories toward AddApiVersioning().AddOpenApi()) suppressed - FSH registers one OpenAPI document per version by design. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
1 task
marcelo-maciel
added a commit
to marcelo-maciel/dotnet-starter-kit
that referenced
this pull request
Sep 25, 2026
…y covers SonarAnalyzer 10.34 (fullstackhero#1396) reports it as S8969, which fails the build under TreatWarningsAsErrors.
This was referenced Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Upgrades .NET Aspire 13.4.0 → 13.5.4 and every NuGet package to its latest stable version, handling each break the upgrade surfaced.
Package changes
Aspire.Hosting.*Microsoft.Extensions.Caching.Hybrid/Http.Resilience/ServiceDiscoveryMicrosoft.OpenApi2.9.0 → 2.12.2 (stays 2.x),System.Security.Cryptography.Xml→ 10.0.12,SQLitePCLRaw.lib.e_sqlite3→ 3.53.3,MessagePack→ 2.5.305 (stays 2.x for SignalR)Deliberately not taken: .NET 11 previews/RCs (
System.Security.Cryptography.Xml, SourceLink,System.CommandLine3.0), theSpectre.Console.Cli1.0 alpha,Microsoft.OpenApi3.x andMessagePack3.x (both kept on 2.x on purpose, see the props comments).Breaks handled
!operators. This is compile-time only with no runtime effect, and the compiler verifies every removal. There were 4 false positives where Sonar and the compiler disagreed: the Hangfire basic-auth filter now usesheader.ToString(), and the idempotency test fakes now put!on the cast result.TenantProvisioningServicenow passesCancellationToken.Noneexplicitly into the Hangfire job expression. Hangfire injects its own token at run time, so the request token must not flow into the job.AddApiVersioning().AddOpenApi()) are suppressed inDirectory.Build.props. FSH registers one OpenAPI document per version by design, and moving to the new integration is a separate change.dotnet runwith NuGet-restored DCP/dashboard.!removals in Jobs/Quota/Storage and the Hangfire filter line above. There are no API or behaviour changes.ServiceProvider→Services,PublishAsConnectionString,TerminalOptions, …) apply to our AppHost. SE.Redis 3's one behaviour change (Executenow enforcesAllowAdmin) doesn't apply either, since we never callExecute.Test plan
dotnet build src/FSH.Starter.slnx -c Release --no-incremental: 0 warnings, 0 errorsdotnet test src/FSH.Starter.slnx: 1,950 / 1,950 passed across 15 test projects, including 764 Testcontainers integration tests (Postgres + Redis, with the HybridCache/Redis tests on SE.Redis 3/RESP3)dotnet run --project src/Host/FSH.Starter.AppHost: migrator, demo seeder, RustFS init, API and both SPAs come up. Existing persistent volumes are reused (Postgres image stayspostgres:18.3, so no volume break)./health/readyis fully Healthy: Postgres, Valkey, Hangfire, and all 4 tenants at head migration. OpenAPI and Scalar are served, and the Hangfire/jobsbasic auth works (200 with credentials, 401 without).Pre-existing issues found during E2E (not caused by this PR, not fixed here)
/apiproxy inclients/admin/vite.config.tshas nows: true, so the SignalR WebSocket upgrade never reaches the API and the socket hangs before the handshake.<p>inside a<div>, which triggers a React nesting warning in the console.🤖 Generated with Claude Code