Skip to content

Bump Google.Protobuf and 11 others#110

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/src/accounting/nuget-production-dependencies-59e7636d27
Open

Bump Google.Protobuf and 11 others#110
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/src/accounting/nuget-production-dependencies-59e7636d27

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github May 26, 2026

Updated Google.Protobuf from 3.34.1 to 3.35.0.

Release notes

Sourced from Google.Protobuf's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Grpc.AspNetCore from 2.67.0 to 2.80.0.

Release notes

Sourced from Grpc.AspNetCore's releases.

2.80.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.76.0...v2.80.0

2.80.0-pre1

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.76.0...v2.80.0-pre1

2.76.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.71.0...v2.76.0

2.76.0-pre1

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.71.0...v2.76.0-pre1

2.71.0

What's Changed

Full Changelog: grpc/grpc-dotnet@v2.70.0...v2.71.0

2.71.0-pre1

What's Changed

Full Changelog: grpc/grpc-dotnet@v2.70.0...v2.71.0-pre1

2.70.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.67.0...v2.70.0

Commits viewable in compare view.

Updated Grpc.AspNetCore.HealthChecks from 2.67.0 to 2.80.0.

Release notes

Sourced from Grpc.AspNetCore.HealthChecks's releases.

2.80.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.76.0...v2.80.0

2.80.0-pre1

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.76.0...v2.80.0-pre1

2.76.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.71.0...v2.76.0

2.76.0-pre1

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.71.0...v2.76.0-pre1

2.71.0

What's Changed

Full Changelog: grpc/grpc-dotnet@v2.70.0...v2.71.0

2.71.0-pre1

What's Changed

Full Changelog: grpc/grpc-dotnet@v2.70.0...v2.71.0-pre1

2.70.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.67.0...v2.70.0

Commits viewable in compare view.

Updated Grpc.Net.Client from 2.76.0 to 2.80.0.

Release notes

Sourced from Grpc.Net.Client's releases.

2.80.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.76.0...v2.80.0

2.80.0-pre1

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.76.0...v2.80.0-pre1

Commits viewable in compare view.

Updated Grpc.Tools from 2.68.1 to 2.80.0.

Release notes

Sourced from Grpc.Tools's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.TestHost from 10.0.7 to 10.0.8.

Release notes

Sourced from Microsoft.AspNetCore.TestHost's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Logging from 10.0.7 to 10.0.8.

Release notes

Sourced from Microsoft.Extensions.Logging's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.NET.Test.Sdk from 18.5.0 to 18.6.0.

Release notes

Sourced from Microsoft.NET.Test.Sdk's releases.

18.6.0

What's Changed

Changes to tests and infra

18.5.1

What's Changed

Full Changelog: microsoft/vstest@v18.5.0...v18.5.1

Commits viewable in compare view.

Updated OpenFeature from 2.12.0 to 2.13.0.

Release notes

Sourced from OpenFeature's releases.

2.13.0

2.13.0 (2026-04-30)

🐛 Bug Fixes

  • add missing variant dimension in MetricsHook metrics (#​742) (dad175d)
  • fix 'occured' -> 'occurred' in XML doc comment (#​743) (178f836)
  • security: update dependency opentelemetry.exporter.opentelemetryprotocol to 1.15.3 [security] (#​746) (ec94acf)

✨ New Features

Commits viewable in compare view.

Updated OpenFeature.Hosting from 2.12.0 to 2.13.0.

Release notes

Sourced from OpenFeature.Hosting's releases.

2.13.0

2.13.0 (2026-04-30)

🐛 Bug Fixes

  • add missing variant dimension in MetricsHook metrics (#​742) (dad175d)
  • fix 'occured' -> 'occurred' in XML doc comment (#​743) (178f836)
  • security: update dependency opentelemetry.exporter.opentelemetryprotocol to 1.15.3 [security] (#​746) (ec94acf)

✨ New Features

Commits viewable in compare view.

Updated OpenFeature.Providers.Flagd from 0.6.0 to 0.6.1.

Updated StackExchange.Redis from 2.12.14 to 2.13.1.

Release notes

Sourced from StackExchange.Redis's releases.

No release notes found for this version range.

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Open in Devin Review

Summary by cubic

Upgrade core dependencies in accounting and cart to current minor/patch releases, including the gRPC stack, Protobuf, OpenFeature, Redis, and test/logging tooling. This removes the old gRPC pin in cart and picks up bug fixes and .NET compatibility updates.

  • Dependencies
    • gRPC stack to 2.80.0: Grpc.AspNetCore, Grpc.AspNetCore.HealthChecks, Grpc.Net.Client, Grpc.Tools
    • Google.Protobuf to 3.35.0
    • OpenFeature to 2.13.0: OpenFeature, OpenFeature.Hosting; OpenFeature.Providers.Flagd to 0.6.1
    • StackExchange.Redis to 2.13.1
    • Test tooling: Microsoft.NET.Test.Sdk 18.6.0, Microsoft.AspNetCore.TestHost 10.0.8
    • Microsoft.Extensions.Logging to 10.0.8

Written for commit ef39c6a. Summary will update on new commits. Review in cubic

Bumps Google.Protobuf from 3.34.1 to 3.35.0
Bumps Grpc.AspNetCore from 2.67.0 to 2.80.0
Bumps Grpc.AspNetCore.HealthChecks from 2.67.0 to 2.80.0
Bumps Grpc.Net.Client from 2.76.0 to 2.80.0
Bumps Grpc.Tools from 2.68.1 to 2.80.0
Bumps Microsoft.AspNetCore.TestHost from 10.0.7 to 10.0.8
Bumps Microsoft.Extensions.Logging from 10.0.7 to 10.0.8
Bumps Microsoft.NET.Test.Sdk from 18.5.0 to 18.6.0
Bumps OpenFeature from 2.12.0 to 2.13.0
Bumps OpenFeature.Hosting from 2.12.0 to 2.13.0
Bumps OpenFeature.Providers.Flagd from 0.6.0 to 0.6.1
Bumps StackExchange.Redis from 2.12.14 to 2.13.1

---
updated-dependencies:
- dependency-name: Google.Protobuf
  dependency-version: 3.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-production-dependencies
- dependency-name: Grpc.Tools
  dependency-version: 2.80.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-production-dependencies
- dependency-name: Microsoft.Extensions.Logging
  dependency-version: 10.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-production-dependencies
- dependency-name: Grpc.AspNetCore
  dependency-version: 2.80.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-production-dependencies
- dependency-name: Grpc.AspNetCore.HealthChecks
  dependency-version: 2.80.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-production-dependencies
- dependency-name: OpenFeature
  dependency-version: 2.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-production-dependencies
- dependency-name: OpenFeature.Providers.Flagd
  dependency-version: 0.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-production-dependencies
- dependency-name: OpenFeature.Hosting
  dependency-version: 2.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-production-dependencies
- dependency-name: StackExchange.Redis
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-production-dependencies
- dependency-name: Grpc.Net.Client
  dependency-version: 2.80.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-production-dependencies
- dependency-name: Microsoft.AspNetCore.TestHost
  dependency-version: 10.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-production-dependencies
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels May 26, 2026
Copy link
Copy Markdown

@devin-ai-integration devin-ai-integration Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 3 potential issues.

Open in Devin Review

Comment thread src/cart/src/cart.csproj
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: CHANGELOG.md and documentation not updated with this PR

The CONTRIBUTING.md guidelines state that PRs should update the Changelog and documentation to reflect new changes. This PR does not appear to update the CHANGELOG.md. For a routine dependency bump PR this is likely acceptable as a trivial change, but it's worth noting for completeness with the project's contribution guidelines.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread src/cart/src/cart.csproj
Comment on lines +19 to +20
<PackageReference Include="Grpc.AspNetCore" Version="2.80.0" />
<PackageReference Include="Grpc.AspNetCore.HealthChecks" Version="2.80.0" />
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Stale comment contradicts Grpc.AspNetCore version bump from 2.67 to 2.80

Line 18 has a comment <!-- Keeping Grpc.AspNetCore* to 2.67 due to https://github.com/grpc/grpc/issues/38538 --> that explicitly states the package should be pinned to version 2.67 due to a known gRPC issue. However, the PR bumps Grpc.AspNetCore and Grpc.AspNetCore.HealthChecks from 2.67.0 to 2.80.0 on lines 19-20 without updating or removing this comment. This creates two problems: (1) if the referenced issue is still relevant, this upgrade could re-introduce the bug; (2) if the issue has been resolved, the now-stale comment will mislead future developers into thinking the version is still pinned at 2.67 and discourage further upgrades.

Prompt for agents
The comment on line 18 of src/cart/src/cart.csproj says the Grpc.AspNetCore packages are pinned to 2.67 due to https://github.com/grpc/grpc/issues/38538, but the PR bumps them to 2.80.0. Either: (1) verify that the referenced issue (grpc/grpc#38538) has been fixed in a version <= 2.80.0, and if so remove or update the comment to note the issue has been resolved; or (2) if the issue is still open, revert the version back to 2.67.0.
Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

<PackageReference Include="Grpc.Net.Client" Version="2.76.0" />
<PackageReference Include="Microsoft.AspNetCore.TestHost" Version="10.0.7" />
<PackageReference Include="Microsoft.NET.Test.Sdk" Version="18.5.0" />
<PackageReference Include="Grpc.Net.Client" Version="2.80.0" />
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Grpc package versions are now consistent across projects

The PR aligns Grpc-related package versions across all three project files to 2.80.0: Grpc.Tools in Accounting.csproj:15, Grpc.AspNetCore and Grpc.AspNetCore.HealthChecks in cart.csproj:19-20, and Grpc.Net.Client in cart.tests.csproj:8. Previously, these were at different versions (2.68.1, 2.67.0, and 2.76.0 respectively). The alignment to a single version is a positive consistency improvement, though the stale pinning comment in cart.csproj should be addressed.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants