Skip to content

chore(deps): consolidated dependency updates (supersedes 8 dependabot PRs) - #348

Merged
mivano merged 2 commits into
mainfrom
chore/dependency-updates
Aug 16, 2026
Merged

mivano merged 2 commits into
mainfrom
chore/dependency-updates

Conversation

@mivano

@mivano mivano commented Aug 16, 2026

Copy link
Copy Markdown
Owner

Consolidates the eight open dependabot PRs into one branch, bumping to the latest stable version of each package (rather than dependabot's older proposals, which would otherwise be re-opened next cycle).

NuGet

Package From To Dependabot PR
Microsoft.Extensions.DependencyInjection (src + tests) 10.0.8 10.0.11 #336 (proposed 10.0.9)
Microsoft.Extensions.Http.Polly 10.0.8 10.0.11 #337 (proposed 10.0.9)
Polly 8.6.6 8.7.0 #338
Microsoft.NET.Test.Sdk 18.6.0 18.9.0 #342 (proposed 18.7.0)
Spectre.Console 0.55.2 0.57.2 #340 (proposed 0.57.0)
Spectre.Console.Json 0.55.2 0.57.2 #340 (proposed 0.57.0)

GitHub Actions

Action From To Dependabot PR
actions/checkout v6 v7 #341
actions/setup-dotnet v5 v6 #345
github/issue-metrics v4 v5 #344

Notes on the Spectre bump

Spectre.Console.Cli deliberately stays at 0.55.0 — there is no stable 0.56/0.57 release; the package has moved to 1.0.0-alpha.*. Its nuspec declares Spectre.Console >= 0.55.0 (a minimum, not an exact pin), so NuGet unifies cleanly on 0.57.2 with no NU1605/NU1608. Spectre.Console and Spectre.Console.Json are kept in lockstep, as they must be.

Action major-version notes

  • actions/setup-dotnet v6 — ESM migration + dependency upgrades only; no input renames.
  • github/issue-metrics v5 — the "breaking change" is an internal github3.py → PyGithub migration; action inputs are unchanged.
  • actions/checkout v7 — no input changes affecting this repo.

Verification

  • Both target frameworks (net8.0, net10.0) compile clean — 0 errors, no new NuGet warnings.
  • 286/286 tests pass on net10.0. (net8.0 tests could not be executed locally — no .NET 8 runtime on this machine — but the TFM builds; CI covers it.)
  • --help output with Spectre 0.57.2 is byte-identical to the 0.55.2 output, confirming no rendering regression from the 0.x minor bump.

🤖 Generated with Claude Code

mivano and others added 2 commits August 16, 2026 21:19
- Microsoft.Extensions.DependencyInjection 10.0.8 -> 10.0.11 (src + tests)
- Microsoft.Extensions.Http.Polly 10.0.8 -> 10.0.11
- Polly 8.6.6 -> 8.7.0
- Microsoft.NET.Test.Sdk 18.6.0 -> 18.9.0
- actions/checkout v6 -> v7
- actions/setup-dotnet v5 -> v6
- github/issue-metrics v4 -> v5

Supersedes dependabot PRs #336, #337, #338, #341, #342, #344, #345.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Spectre.Console.Cli stays at 0.55.0 (no stable 0.56/0.57 release; it has
moved to 1.0.0-alpha). Its dependency on Spectre.Console is a minimum
(>= 0.55.0), not an exact pin, so NuGet unifies on 0.57.2 without a
downgrade warning.

Verified: both TFMs compile, 286 tests pass on net10.0, and `--help`
rendering is byte-identical to the 0.55.2 output.

Supersedes dependabot PR #340.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings August 16, 2026 19:36
@github-actions

Copy link
Copy Markdown

File Coverage Lines Branches Missing
All files 29% 28% 30% ❌

Minimum allowed coverage is 75%

Generated by 🐒 cobertura-action against a85cde1

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR consolidates multiple Dependabot updates into a single dependency-refresh branch for Azure Cost CLI, updating key NuGet packages used by the CLI and its test project, and bumping several GitHub Actions used in CI/workflows.

Changes:

  • Bump core NuGet dependencies in the CLI project (DI, Http.Polly, Polly, Spectre.Console + Json).
  • Bump test-time NuGet dependencies in the test project (Microsoft.NET.Test.Sdk, DI).
  • Update GitHub Actions major versions for checkout, setup-dotnet, and issue-metrics across relevant workflows.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated no comments.

Show a summary per file
File Description
tests/AzureCostCli.Tests/AzureCostCli.Tests.csproj Updates test SDK and DI package versions for the test project.
src/azure-cost-cli.csproj Updates runtime/library dependencies (DI, Polly, Spectre.Console).
.github/workflows/issue-metrics.yml Bumps github/issue-metrics action to v5.
.github/workflows/dotnet.yml Bumps actions/checkout to v7 and actions/setup-dotnet to v6 for CI.
.github/workflows/dotnet-build-on-tag.yml Bumps actions/checkout to v7 and actions/setup-dotnet to v6 for release builds.
.github/workflows/codeql.yml Bumps actions/checkout to v7 and actions/setup-dotnet to v6 for CodeQL analysis workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants