Repository navigation
chore(deps): consolidated dependency updates (supersedes 8 dependabot PRs) - #348
Merged
Merged
Conversation
- Microsoft.Extensions.DependencyInjection 10.0.8 -> 10.0.11 (src + tests) - Microsoft.Extensions.Http.Polly 10.0.8 -> 10.0.11 - Polly 8.6.6 -> 8.7.0 - Microsoft.NET.Test.Sdk 18.6.0 -> 18.9.0 - actions/checkout v6 -> v7 - actions/setup-dotnet v5 -> v6 - github/issue-metrics v4 -> v5 Supersedes dependabot PRs #336, #337, #338, #341, #342, #344, #345. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Spectre.Console.Cli stays at 0.55.0 (no stable 0.56/0.57 release; it has moved to 1.0.0-alpha). Its dependency on Spectre.Console is a minimum (>= 0.55.0), not an exact pin, so NuGet unifies on 0.57.2 without a downgrade warning. Verified: both TFMs compile, 286 tests pass on net10.0, and `--help` rendering is byte-identical to the 0.55.2 output. Supersedes dependabot PR #340. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Minimum allowed coverage is Generated by 🐒 cobertura-action against a85cde1 |
Contributor
There was a problem hiding this comment.
Pull request overview
This PR consolidates multiple Dependabot updates into a single dependency-refresh branch for Azure Cost CLI, updating key NuGet packages used by the CLI and its test project, and bumping several GitHub Actions used in CI/workflows.
Changes:
- Bump core NuGet dependencies in the CLI project (DI, Http.Polly, Polly, Spectre.Console + Json).
- Bump test-time NuGet dependencies in the test project (Microsoft.NET.Test.Sdk, DI).
- Update GitHub Actions major versions for checkout, setup-dotnet, and issue-metrics across relevant workflows.
Reviewed changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| tests/AzureCostCli.Tests/AzureCostCli.Tests.csproj | Updates test SDK and DI package versions for the test project. |
| src/azure-cost-cli.csproj | Updates runtime/library dependencies (DI, Polly, Spectre.Console). |
| .github/workflows/issue-metrics.yml | Bumps github/issue-metrics action to v5. |
| .github/workflows/dotnet.yml | Bumps actions/checkout to v7 and actions/setup-dotnet to v6 for CI. |
| .github/workflows/dotnet-build-on-tag.yml | Bumps actions/checkout to v7 and actions/setup-dotnet to v6 for release builds. |
| .github/workflows/codeql.yml | Bumps actions/checkout to v7 and actions/setup-dotnet to v6 for CodeQL analysis workflow. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This was referenced Aug 16, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Consolidates the eight open dependabot PRs into one branch, bumping to the latest stable version of each package (rather than dependabot's older proposals, which would otherwise be re-opened next cycle).
NuGet
GitHub Actions
Notes on the Spectre bump
Spectre.Console.Clideliberately stays at 0.55.0 — there is no stable 0.56/0.57 release; the package has moved to1.0.0-alpha.*. Its nuspec declaresSpectre.Console >= 0.55.0(a minimum, not an exact pin), so NuGet unifies cleanly on 0.57.2 with noNU1605/NU1608.Spectre.ConsoleandSpectre.Console.Jsonare kept in lockstep, as they must be.Action major-version notes
actions/setup-dotnetv6 — ESM migration + dependency upgrades only; no input renames.github/issue-metricsv5 — the "breaking change" is an internalgithub3.py→PyGithubmigration; action inputs are unchanged.actions/checkoutv7 — no input changes affecting this repo.Verification
net8.0,net10.0) compile clean — 0 errors, no new NuGet warnings.net10.0. (net8.0tests could not be executed locally — no .NET 8 runtime on this machine — but the TFM builds; CI covers it.)--helpoutput with Spectre 0.57.2 is byte-identical to the 0.55.2 output, confirming no rendering regression from the 0.x minor bump.🤖 Generated with Claude Code