Skip to content

chore(deps): upgrade Aspire to 13.5.4 and all NuGet packages to latest - #1396

Merged
iammukeshm merged 1 commit into
mainfrom
chore/upgrade-aspire-and-packages
Sep 25, 2026
Merged

iammukeshm merged 1 commit into
mainfrom
chore/upgrade-aspire-and-packages

Conversation

@iammukeshm

Copy link
Copy Markdown
Member

Summary

Upgrades .NET Aspire 13.4.0 → 13.5.4 and every NuGet package to its latest stable version, handling each break the upgrade surfaced.

Package changes

Area From → To
Aspire AppHost SDK + Aspire.Hosting.* 13.4.0 → 13.5.4 (upgraded together — mixed 13.4/13.5 packages fail at runtime)
.NET 10 platform (ASP.NET Core, EF Core, Extensions, SignalR, Identity…) 10.0.8 → 10.0.12
Microsoft.Extensions.Caching.Hybrid / Http.Resilience / ServiceDiscovery 10.6.0 → 10.10.0
StackExchange.Redis (major) 2.13.17 → 3.3.1 — same API as 2.13.17, new IO core, RESP3 by default
NSubstitute (major) 5.3.0 → 6.2.0 — no removed APIs in use
xunit.runner.visualstudio (major) 3.1.5 → 4.0.0 — still runs xUnit v2
OpenTelemetry 1.15.x → 1.19.x (EF/Redis instrumentation betas → latest beta)
Asp.Versioning 10.0.0 → 10.2.x
Npgsql EF / Npgsql.OpenTelemetry 10.0.1/10.0.2 → 10.0.3
Scalar, QuestPDF, Hangfire, MailKit/MimeKit, AWSSDK.S3, Testcontainers, Finbuckle, Serilog, SonarAnalyzer, MS.NET.Test.Sdk, FeatureManagement, RabbitMQ.Client, Spectre.Console, System.CommandLine, JWT, coverlet → latest stable
Security pins (kept on their lines) Microsoft.OpenApi 2.9.0 → 2.12.2 (stays 2.x), System.Security.Cryptography.Xml → 10.0.12, SQLitePCLRaw.lib.e_sqlite3 → 3.53.3, MessagePack → 2.5.305 (stays 2.x for SignalR)

Deliberately not taken: .NET 11 previews/RCs (System.Security.Cryptography.Xml, SourceLink, System.CommandLine 3.0), the Spectre.Console.Cli 1.0 alpha, Microsoft.OpenApi 3.x and MessagePack 3.x (both kept on 2.x on purpose, see the props comments).

Breaks handled

  • Sonar S8969 (new rule, fatal under warnings-as-errors): removed 157 redundant ! operators. This is compile-time only with no runtime effect, and the compiler verifies every removal. There were 4 false positives where Sonar and the compiler disagreed: the Hangfire basic-auth filter now uses header.ToString(), and the idempotency test fakes now put ! on the cast result.
  • Sonar S8949 (new rule): TenantProvisioningService now passes CancellationToken.None explicitly into the Hangfire job expression. Hangfire injects its own token at run time, so the request token must not flow into the job.
  • AV0029/AV0030 (Asp.Versioning 10.2 advisories nudging toward AddApiVersioning().AddOpenApi()) are suppressed in Directory.Build.props. FSH registers one OpenAPI document per version by design, and moving to the new integration is a separate change.
  • ASPIRE010 (Aspire 13.5) is suppressed on the AppHost, following the official guidance for projects that run via dotnet run with NuGet-restored DCP/dashboard.
  • BuildingBlocks touched (protected): the only changes there are ! removals in Jobs/Quota/Storage and the Hangfire filter line above. There are no API or behaviour changes.
  • None of Aspire 13.5's documented breaking changes (ServiceProvider→Services, PublishAsConnectionString, TerminalOptions, …) apply to our AppHost. SE.Redis 3's one behaviour change (Execute now enforces AllowAdmin) doesn't apply either, since we never call Execute.

Test plan

  • dotnet build src/FSH.Starter.slnx -c Release --no-incremental: 0 warnings, 0 errors
  • dotnet test src/FSH.Starter.slnx: 1,950 / 1,950 passed across 15 test projects, including 764 Testcontainers integration tests (Postgres + Redis, with the HybridCache/Redis tests on SE.Redis 3/RESP3)
  • Full Aspire 13.5.4 stack via dotnet run --project src/Host/FSH.Starter.AppHost: migrator, demo seeder, RustFS init, API and both SPAs come up. Existing persistent volumes are reused (Postgres image stays postgres:18.3, so no volume break).
  • /health/ready is fully Healthy: Postgres, Valkey, Hangfire, and all 4 tenants at head migration. OpenAPI and Scalar are served, and the Hangfire /jobs basic auth works (200 with credentials, 401 without).
  • API flows on the live stack: token issue and refresh (root/acme/globex), tenants, users, roles, audits, billing plans, webhooks, files, chat, tickets, notifications, and a brand create → read → delete round trip (cache invalidation + outbox).
  • Headless Playwright against the live stack (no mocks): admin (root) visited 10 routes and dashboard (acme) visited 19 routes, with 486 API calls, 0 × 5xx/401, and no unexpected logouts. The dashboard SignalR hub connects over WSS and completes its handshake.

Pre-existing issues found during E2E (not caused by this PR, not fixed here)

  • Admin realtime is broken in Vite dev: the /api proxy in clients/admin/vite.config.ts has no ws: true, so the SignalR WebSocket upgrade never reaches the API and the socket hangs before the handshake.
  • The dashboard Topbar renders a <p> inside a <div>, which triggers a React nesting warning in the console.

🤖 Generated with Claude Code

- Aspire.AppHost.Sdk + Aspire.Hosting.* 13.4.0 -> 13.5.4 (upgraded together;
  mixed 13.4/13.5 packages fail at runtime). Suppress ASPIRE010 - we run via
  `dotnet run` with NuGet-restored DCP/dashboard, not the Aspire CLI bundle.
- .NET 10 platform packages 10.0.8 -> 10.0.12, EF Core 10.0.12, Npgsql EF 10.0.3,
  OpenTelemetry 1.19, Asp.Versioning 10.2, Scalar 2.17, QuestPDF 2026.9,
  Hangfire 1.8.25, MailKit/MimeKit 4.18, AWSSDK.S3 4.0.103, Testcontainers 4.15,
  SonarAnalyzer 10.34, and the rest to latest stable.
- Majors: StackExchange.Redis 3.3.1 (same API as 2.13.17, new IO core, RESP3 by
  default), NSubstitute 6.2.0, xunit.runner.visualstudio 4.0.0 (still runs v2).
- Security pins bumped within their lines: Microsoft.OpenApi 2.12.2 (stays 2.x),
  System.Security.Cryptography.Xml 10.0.12, SQLitePCLRaw.lib.e_sqlite3 3.53.3,
  MessagePack 2.5.305.
- SonarAnalyzer S8969 (new): removed 157 redundant null-forgiving operators;
  compile-time only. Hangfire basic-auth filter uses header.ToString() where
  Sonar and the compiler disagreed.
- S8949 (new): TenantProvisioningService passes CancellationToken.None
  explicitly into the Hangfire job expression.
- AV0029/AV0030 (Asp.Versioning 10.2 advisories toward
  AddApiVersioning().AddOpenApi()) suppressed - FSH registers one OpenAPI
  document per version by design.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@iammukeshm
iammukeshm merged commit a0813e6 into main Sep 25, 2026
16 checks passed
@iammukeshm
iammukeshm deleted the chore/upgrade-aspire-and-packages branch September 25, 2026 14:14
marcelo-maciel added a commit to marcelo-maciel/dotnet-starter-kit that referenced this pull request Sep 25, 2026
…y covers

SonarAnalyzer 10.34 (fullstackhero#1396) reports it as S8969, which fails the build under TreatWarningsAsErrors.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant