Skip to content

Bump the nuget-all group with 26 updates - #407

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/dot-config/nuget-all-6063d97732
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/dot-config/nuget-all-6063d97732

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown

Updated docfx from 2.78.5 to 2.81.0.

Release notes

Sourced from docfx's releases.

2.81.0

What's Changed

✨ Features & Platform Support

  • Allow custom templates to override search.min.js in the modern template by @​filzrev in #​10055.
  • Add metadata.sourceLinkExclude to exclude selected source paths from View Source links without removing API documentation by @​vicancy in #​11141.
  • Record the DocFX build version in the docfx_version field of manifest.json by @​vicancy in #​11162.
  • Add a .NET 11 RC target, including support for the .NET 11 Razor source generator, while retaining .NET 8, 9, and 10 targets by @​vicancy and @​filzrev in #​11176 and #​11182.

⚡ Performance & Reliability

  • Reduce JavaScript template processing overhead and memory allocations by reusing parsed scripts and improving model conversion. Add execution limits to prevent runaway scripts from hanging builds by @​lahma in #​11084.
  • Avoid unnecessary exceptions and repeated file reads when loading toc.yml by @​filzrev in #​9974.

🐛 Bug Fixes

  • Restore source links for partial types extended by source generators by @​vicancy in #​11141.
  • Fix local namespace links in managed reference documentation by resolving them through xrefs during site generation by @​vicancy in #​11163.
  • Preserve nested XML blocks when inserting Markdown separators, preventing content from incorrectly rendering as code blocks by @​vicancy in #​11175.
  • Preserve explicit false and 0 values when overwriting nullable properties by @​vicancy in #​11181.

📦 Dependency Updates

Upgrade Notes

Custom JavaScript template preprocessors now enforce a 30-second timeout and a 50-million-statement limit for each getOptions or transform invocation. Long-running custom scripts may need adjustment.

Full Changelog: dotnet/docfx@v2.80.1...v2.81.0

2.80.1

What's Changed

💪 Other Changes

New Contributors

Full Changelog: dotnet/docfx@v2.78.6...v2.80.1

2.78.6

What's Changed

💪 Other Changes

Commits viewable in compare view.

Updated Jint from 4.15.3 to 4.16.4.

Release notes

Sourced from Jint's releases.

4.16.4

Jint 4.16.4 is a maintenance release from the 4.x branch. It backports correctness and conformance fixes from main — three of them for scripts that could end the host process — together with a few measured performance improvements, and nothing in it changes an existing API or an existing default. If you are on 4.16.3 it is a drop-in update — every public signature is the one 4.16.0 shipped, on all five target frameworks, and the per-framework snapshots in Jint.Tests.PublicInterface/Verify/ are unchanged. main remains 5.0.0 development; what is coming there is recorded as it lands in docs/v5-migration.md.

Highlights

A number reads as the same double on every target framework. Before .NET 9, the runtime's ulong-to-double and string-to-double conversions double-round, and Jint inherited that: a whole-number literal in [2⁶³, 2⁶⁴) held a different double on .NET Framework and .NET 8 than on .NET 10 (#​3531); parseFloat, Number and JSON.parse mis-rounded past their integer window on .NET Framework, and JSON.parse('1e999') threw a CLR OverflowException out of the engine instead of answering Infinity (#​3535); a fraction or exponent literal could land one ULP away on .NET Framework (#​3538); and parseInt and wide radix literals now hold the Number nearest the integer they denote on every framework, with a legacy octal no longer re-read as decimal (#​3537). The string-to-number lanes and trim now accept exactly the white space the parser does — U+0085 NEL no longer counts, and a byte-order mark no longer breaks Number or BigInt (#​3542) — and an exponent scan no longer clamps at 10⁶ (#​3593). All six arrive together as #​4120, because they share one parser. This changes numeric results — to the correct ones. The literal and string-to-number fixes change answers on .NET Framework only; parseInt, radix literals, the white-space set and the exponent clamp change them on every framework.

BigInt('+12') is 12n. The decimal spelling of a StringIntegerLiteral may carry a sign, so a leading + is accepted there and only there; BigInt('+0x10') stays a SyntaxError (#​4121).

A split keeps its segments when a constraint runs script. String.prototype.split filled a thread-shared scratch list and checks constraints every 10,000 segments; a host Constraint that ran script on the same thread could clear the list an outer split was still filling, which then returned only the segments added afterwards (#​4122).

An overload is not a fit for a number it cannot hold. Overload scoring gated float, short, byte and their kin on the value fitting, but not int and long — so 3000000000 was a perfect match for an int parameter, the wider overload beside it was never tried, and the host saw a CLR OverflowException rather than a catchable JavaScript error (#​4123).

Intl's locale lookup stops paying for a culture it does not need. BestAvailableLocale resolved a CultureInfo on every truncation step even though the available-locale set answers almost every lookup by itself; it now resolves one only when the set cannot answer (#​4124).

Intl.Locale canonicalizes every Unicode extension keyword value. UTS #​35 canonicalizes a keyword's value in two halves — the CLDR bcp47 aliases, and the removal of a value of "true" — and Jint did only the first, while Intl.Locale's own tag scanner did neither. So en-u-ca-true kept its true, en-u-kb-yes kept its yes although the data aliases it to true, and en-u-ks-primary was never aliased to level1 on the tag path. The firstDayOfWeek option was read as a Number before a String and cast to int, so 0.5 resolved to "sun" where the spec rejects it, and NaN and Infinity became whatever the framework's cast made of them — which differed between .NET and .NET Framework (#​4156).

An object used as a rotating cache stops compacting forever. A property removed from an object's store leaves a tombstone, so that a re-added key keeps its creation order. Removing the newest entry already reclaimed its slot; removing the oldest — the shape of a bounded cache, a fresh name in and the oldest out — left a hole each time, and the table compacted every capacity − live additions although the live set never grew: a 16-key rotation settled on a capacity of 64 and compacted 209 times per 10,000 steps. The entries are now a window that may wrap around the array, so a removal at either end retires its slot; the same rotation never resizes and settles on 32 (#​4155).

Chains that script can make as long as it likes no longer end the process. Resolving a property through a prototype chain recursed one native frame per link, so a 20,000-deep { __proto__: x } chain overflowed the native stack on a read, a write, an in or a with lookup and ended the process — nothing thrown, nothing for a catch to see (#​4170, from #​4078; issue #​4076, reported by @​Tielem). [[Get]], [[Set]] and [[HasProperty]] now walk the chain in a loop, so an ordinary or shaped-host-prototype chain of any depth simply answers. Function.prototype.bind chains had the same shape in IsConstructor and in the realm lookup new and Reflect.construct perform, and those are loops now too (#​4169, from #​4165); on .NET Framework the JIT happened to turn both into tail calls, so the process death was a .NET 8 / .NET 10 one.

Two chains cannot be flattened, because each link has work of its own to do on the way back out: a proxy forwarding to a proxy, and host object wrappers stacked on each other (#​4170, from #​4125; issue #​4087). Those are probed instead, and raise a catchable RangeError — when Options.Constraints.StackOverflowGuard is on. On 4.x that guard remains opt-in (it becomes the default only in 5.0), so an engine left at its defaults still ends the process on a deep enough proxy chain. If you run script you do not control, turn the guard on; with it on, a 20,000-link proxy chain used as an array's constructor or as Reflect.construct's newTarget now raises RangeError where it used to end the process.

% stops allocating for numbers. The remainder operator now takes the unboxed numeric lane multiplication and division already used, so sum += i % 97 reads a numeric counter without materialising a JsNumber per step — on the benchmark's arithmetic loop, allocation per run drops from 2.87 MB to under 1 KB (#​4167, from #​4154).

Intl.Locale.prototype.getWeekInfo reads the region the specification picks. It read CLDR's week data for the tag's literal region subtag only, so a tag without one got the world's week and the -u-rg- and -u-sd- keywords were ignored. It now follows RegionPreference: a -u-rg- override, then the region subtag, then a -u-sd- subdivision's region, then the region Add Likely Subtags supplies, then 001. This changes answers — new Intl.Locale('en').getWeekInfo().firstDay is now 7 (en is likely en-US, where the week starts on Sunday) rather than 1, and en-US-u-rg-gbzzzz answers 1 rather than 7 — in each case to what the specification and every browser give (#​4168, from #​4163).

Verification

Every backport was verified failing-first: its tests were run against the unfixed 4.x tree on .NET 10 and .NET Framework 4.7.2, then with the change.

PR tests unfixed .NET Framework unfixed .NET 10 after
#​4120 (#​3531) whole-number literals, 22 15 fail 0 fail all pass
#​4120 (#​3535) string to number, 41; JsonTests, 170 22 + 8 fail 0 fail all pass
#​4120 (#​3538) fraction / exponent literals, 50 16 fail 0 fail all pass
#​4120 (#​3537) parseInt, 124; radix literals, 21 96 + 12 fail 96 + 12 fail all pass
#​4120 (#​3542) white space, 35 22 fail 22 fail all pass
#​4120 (#​3593) exponent clamp, 5 1 fail 1 fail all pass
#​4121 StringToBigInt, 46 16 fail 16 fail all pass
#​4122 constraint re-entrancy, 2 1 fail 1 fail all pass
#​4123 numeric overload range, 20 10 fail 10 fail all pass
#​4124 culture lookup count, 8 1 fail 1 fail all pass
#​4155 creation order across rotation, 53 6 fail 6 fail all pass
#​4156 Intl.Locale canonicalization, 81 30 fail 30 fail all pass
#​4167 modulo lane, 8 (semantics only) 0 fail 0 fail all pass — the lane is proven by allocation: 2,873,104 B → 784 B per run
#​4168 getWeekInfo region preference, 26; test262 getWeekInfo region files, 8 13 + 8 fail 13 + 8 fail all pass
#​4169 bound and proxy chain walks, 3 pass (JIT tail-calls) 3 end the process all pass
#​4170 deep prototype (9), shaped-prototype (8), trapless proxy (3) and wrapper (2) chain rows, plus the PlainObject census 12 end the process, 1 fails, census fails 19 end the process, census fails all pass

Release diagnostics on the tagged commit's tree (a19802dda703), in Release: Jint.Tests 7,655 (net10.0) and 7,570 (net472); Jint.Tests.PublicInterface 1,903 and 1,895; Jint.Tests.CommonScripts 28 and 28; Jint.Tests.SourceGenerators 52; the host-contract verification leg (JINT_HOST_CONTRACT_VERIFICATION=1) 7,655 / 7,570 and 1,907 / 1,899 — zero failures anywhere, and the PublicInterface surface snapshots unchanged. test262: 102,509 passed, 0 failed, 175 skipped — the 4.x control plus the eight getWeekInfo cases #​4168 un-excluded. CI passed the same tree on Linux x64, Linux ARM64, Windows, macOS and the host-contract leg.
... (truncated)

4.16.3

Jint 4.16.3 is a maintenance release from the 4.x branch: correctness and conformance fixes backported from main, and nothing that changes an existing API or an existing default. If you are on 4.16.2 it is a drop-in update — every public signature is the one 4.16.0 shipped, on all five target frameworks, and the per-framework snapshots in Jint.Tests.PublicInterface/Verify/ are unchanged. main remains 5.0.0 development; what is coming there is recorded as it lands in docs/v5-migration.md.

Highlights

A long-lived engine stops accumulating what it has already run. Evaluate(string) and Execute(string) parse a fresh Script on every call, and the engine kept every one of them. Three of the four per-engine handler-tree caches already reset wholesale at 2048 entries so a host streaming endless distinct sources cannot grow them without bound; the fourth, _evaluatedScripts, never got that ceiling and held its keys strongly, retaining the AST of every distinct script the engine had ever evaluated — about 528 bytes per call, climbing forever and reclaimed by nothing short of dropping the engine (#​4116). The realm's tagged-template map had the same shape and a harder constraint: Realm._templateMap was a Dictionary<Node, JsArray>, strong on both ends and never cleared, costing roughly 1.35 KB per call for a frozen array and its raw array. A ceiling is no remedy there, because evicting a live template site is script-visible — f() === f() must hold for one site — so it becomes a ConditionalWeakTable<Node, WeakReference<JsArray>>, weak on both halves (#​4119). Both matter most to exactly the embedding that looks innocuous: one engine, kept for the lifetime of the process, handed ad-hoc source.

A suspended frame no longer dereferences what the suspension produced. await and yield suspend by returning a plain undefined, and the enclosing member link turns that into a sentinel reference that every consumer must recognise before reading. Nine did not, so they read undefined.undefined and raised a TypeError inside a frame that was already suspended. AsyncBlockStart swallowed that throw, but not before the statement-list resume position had been cleared on the way out — so the resume replayed the body from the first statement: one extra run of every un-awaited side effect per suspension point, and a re-entrancy guard silently truncating the rest. In a generator nothing swallows it and the TypeError comes straight out of next(). Two shapes were wrong answers rather than repeated ones — (await p).x = 1 rejected the promise, and o[await k] = 1 assigned to the literal key "undefined" instead of the real one — and for await ((await p).a of it) never terminated at all. Optional chaining was not the trigger despite where the report put it: the guarded fast lane needs a literal property name, so every computed member read of an awaited or yielded value fell through, (await p)[0] as much as (await p)[k] (#​4089, reported by @​salihvatanseverv in #​4086).

Verification

Every change was verified failing-first against the unfixed branch. The suspension fix is pinned by 35 new cases in Jint.Tests/Runtime/SuspendedOptionalChainTests.cs: against 4.16.2's code 28 fail and 6 pass on both .NET 10 and .NET Framework 4.7.2, with a 35th — the for await shape — hanging the test host outright rather than failing; after the fix all 35 pass on both. The retention fixes are pinned by Jint.Tests/Runtime/GarbageCollectionTests.cs and TaggedTemplateCacheTests.cs.

Release diagnostics on the tagged commit, in Release: Jint.Tests 7,170 (net10.0) and 7,085 (net472); Jint.Tests.PublicInterface 1,852 and 1,844; Jint.Tests.CommonScripts 28 and 28; Jint.Tests.SourceGenerators 52; the host-contract verification leg (JINT_HOST_CONTRACT_VERIFICATION=1) 7,170 / 7,085 and 1,856 / 1,848 — zero failures anywhere. test262: 102,498 passed, 183 skipped, with three files crossing the engine's default 30-second budget under whole-suite CPU contention and passing in three seconds when run alone.

The paired SunSpider and Dromaeo comparison against 4.16.2 was run after the tag rather than before it, which is a departure from how 4.16.2 was gated; it is recorded here because the result is what the release notes should carry, not the order it arrived in. No row regressed. Fifty-one rows, paired, alternating order, DefaultJob, on an idle machine: the three-round screen left two candidates clearing the sign-agreement and magnitude bar, both of them Dromaeo.StringBase64, and re-measuring those at eight rounds read −1.72% [−3.01, +1.98] and +0.30% [−3.10, +4.26] — no change, with a third parameter combination coming out faster. StringBase64 is the row Jint.Benchmark/AGENTS.md already documents as a three-round false positive, and it behaved as documented. The Cube control rows moved +0.6% to +0.8%, which is this machine's floor on rows the change cannot reach.

Nothing here is a performance change by intent. #​4119 does move a tagged-template lookup from a Dictionary to a ConditionalWeakTable and #​4089 adds suspension checks to several interpreter lanes, and neither is visible above the noise floor.

What's Changed

Full Changelog: sebastienros/jint@v4.16.2...v4.16.3

4.16.2

Jint 4.16.2 is a maintenance release from the 4.x branch: correctness and conformance fixes backported from main, and nothing that changes an existing API or an existing default. If you are on 4.16.1 it is a drop-in update — every public signature is the one 4.16.0 shipped, on all five target frameworks, and the per-framework snapshots in Jint.Tests.PublicInterface/Verify/ are unchanged. main remains 5.0.0 development; what is coming there is recorded as it lands in docs/v5-migration.md.

Highlights

Failures that used to end the process, or never end. A native error raised while a call's arguments are being evaluated is propagated instead of leaving an empty value behind, which on 4.16.1 could recurse until the process died — decodeURIComponent on a malformed sequence was enough (#​4009). Native recursion and the forwarding paths through bound functions and proxies are guarded so a deep native chain raises a catchable error (#​4007). A module graph too deep to link raises an error the host can catch instead of overflowing the stack (#​3548). Temporal and Intl parsing cannot throw an uncatchable RegexMatchTimeoutException because the machine was busy (#​3543), a Temporal difference past a calendar's range raises RangeError instead of spinning forever (#​3555), and the process-wide Intl culture cache and Temporal zone cache are read-only and bounded, with a rejected zone no longer remembered — closing a script-driven unbounded growth (#​3546).

Generators and built-ins, step by step. A yield* delegation reached again by a loop both re-delegates and keeps its place: countdown(3) in a loop no longer hangs, and a delegating generator no longer returns the memoized first result (#​3545). Array.prototype.map and slice hand a @@​species constructor the length ToLength produced, and a non-callable map argument is a TypeError (#​3547). A trailing NUL pads neither a numeric string nor an array index (#​3552). A removed property slot is a tombstone rather than a free slot to reuse, so enumeration order survives a delete-and-readd (#​3318), and LengthOfArrayLike no longer clamps through a uint overload (#​3328).

Interop that answers for the right engine. Two engines in one process no longer decide each other's conversions and operators (#​3559), a host type converter's answer stays with the engine whose converter gave it (#​3563), and a value the host registers on a ShadowRealm — and the members its wrapper builds eagerly — belong to that realm (#​3557). Realm construction state is restored after nesting or a failure (#​4008). Overload selection is by the arguments in hand: an operator overload is chosen that way (#​3611), a params overload is chosen by the array's element type with a failing element declining rather than throwing (#​3782), an overload the argument cannot bind to is not a match, and a host operator that throws reports what it threw (#​3554). An index on a wrapped host collection is one property however it is spelled, and a member filter that hides the indexer hides it (#​3562); a read-only host collection refuses a write with a JavaScript TypeError rather than the CLR's NotSupportedException (#​3556).

Internationalization and Temporal. The Persian calendar extends into proleptic years on its 33-year cycle, so the ends of Temporal's range land in the right Persian year (#​4006); a calendar that counts Gregorian months writes their names (#​3612); and a -u- extension carrying more than one key is read whole (#​3613).

Errors. Only a string-valued stack counts as a pre-existing stack when a JavaScriptException is built, so an accessor or non-string stack on a thrown object no longer breaks error reporting (#​3677, reported by @​jeske).

Every change was verified failing-first against the unfixed branch on both .NET Framework and .NET 10, and the release was gated on a paired SunSpider and Dromaeo comparison against 4.16.1 on an idle machine: no row regressed outside run-to-run noise, most run 1–4 % faster.

What's Changed

Full Changelog: sebastienros/jint@v4.16.1...v4.16.2

4.16.1

Jint 4.16.1 is the first release from the new 4.x maintenance branch, and it marks the point where the two lines separate: main is now 5.0.0 development, and 4.x is where the 4.16.x line continues.

What that means for you. If you are on 4.16.0, this is a drop-in update — it is correctness and conformance work only, no API change and no changed default. Every public signature is the same one 4.16.0 shipped, on all five target frameworks. If you want the 4.x line, take it from 4.x and expect fixes rather than features. If you want to follow where the engine is going, watch main — v5 brings breaking API changes, an opt-in WHATWG web API surface, Web Workers, Node compatibility and a raised .NET Framework floor, and every one of them is recorded as it lands in docs/v5-migration.md.

From this release onward the 4.x public surface is snapshotted per target framework in Jint.Tests.PublicInterface/Verify/, so "did the API move?" is a diff rather than a judgement call — on this branch a diff there is a bug, and comparing those files against main's is the v4→v5 delta.

Highlights

Conformance, from a suite that now runs more of test262. The staging/ directory is generated and executed for the first time (#​3016), which is roughly 2,800 additional cases — largely SpiderMonkey's own suite contributed upstream, covering behaviour the stable directories never reach. Much of the work below is what it found.

Built-ins do what the spec says, step by step. The array built-ins perform the internal methods they name rather than equivalents (#​3066); Array.from honours IsConstructor and a typed array's length write throws (#​3043); an array truncation walks downwards and the generics report the writes they fail (#​3072); argument validation and evaluation order are corrected in five built-ins (#​3069); Map and Set get the [[SetData]] tombstone their traversals are specified over (#​3073); Date.prototype.setTime stores the clipped time value (#​3042); and Array.prototype.values/keys/entries no longer gate on an array-like receiver (#​3236).

Iterators and control flow. A throw from the iterator step no longer closes the iterator (#​3047); the done flag is consulted before stepping again (#​3048); a rejected return() propagates out of an abandoned for await loop (#​3113); an optional-chain short circuit is distinguished from a genuine undefined (#​3040); a computed property key is evaluated even when spelled as a literal (#​3039) and survives an await or yield intact (#​3144, #​3150); and destructuring the rest of an exhausted array yields an empty array rather than 2³² elements (#​3263).

Numeric and string accuracy. Math.acosh, asinh, atanh, cbrt, expm1 and log1p are ported from fdlibm for correctly-rounded results across every target framework (#​3050); toFixed formats from the double's exact value and reads this from [[NumberData]] (#​3071); String.prototype case conversion derives from Jint's own Unicode tables rather than the host's culture data (#​3068); and the regex engine is chosen per subject, with RegExp.prototype.replace no longer rewriting lastIndex (#​3070).

Bounds that hold. JavaScript strings have a maximum length instead of a wrapped array rent (#​3015); a JSON document too long to become a string is refused while it is being built (#​3028); a frame displaced by a proper tail call keeps counting while its trampoline runs, so MaxRecursionDepth cannot be evaded by leaving and re-entering the trampoline (#​3022); and an Atomics waiter is released when nothing can ever notify it again (#​3029).

Error messages no longer run user JavaScript (#​3041) — rendering a message for a value with a script-supplied toString used to invoke it, from inside the failure path.

Internationalization. The five Temporal members the proposal removed are dropped (#​3014), and u-extension options are canonicalized with every date format the spec allows (#​3018).

Two fixes in this release come from @​svenrog — a sloppy function answering its own arguments (#​3061) and the outer link on a parked Function-constructor environment (#​3063).

What's Changed

4.16.0

Jint 4.16.0 is a correctness- and reliability-focused release: alongside asynchronous module loading, proper tail calls and four new iterator built-ins, a pre-tag review swept the whole engine and fixed what it found — including long-standing defects that predate this cycle. No option defaults changed. Behaviour changes to note up front: JSON.stringify and other machine-readable output now format invariantly under every host culture — under Swedish or Finnish locales on .NET 8+ it used to emit a Unicode minus sign no JSON parser accepts; JSON.parse now rejects trailing commas as the grammar requires; bare identifiers at global scope resolve through the global's prototype chain per spec; IModuleLoader.Resolve is consulted once per (referrer, specifier) pair, so a loader using it as a per-import access-control checkpoint should move the check to LoadModule; and an inconsistent sort comparator now finishes with an implementation-defined order on every target framework instead of hanging (net462/netstandard) or throwing a CLR exception at script (net8+).

Highlights

Proper tail calls (#​2975). Strict-mode calls in tail position reuse their frame, so "use strict" tail recursion runs in constant stack — the first ES2015 PTC implementation among the .NET engines.

Asynchronous module loading (#​2872). IAsyncModuleLoader and the AsyncModuleLoader template let a host fetch module source over I/O without blocking a thread; Engine.Modules.StartImport returns an operation a game loop drives via ProcessTasks(), and ImportAsync awaits without holding a thread. The spec's load phase now exists as written, a warm-cache async loader keeps the blocking Import fully synchronous, and the blocking drain wakes on a work-arrived signal instead of polling. A module served over a transport keeps its whole url as Module.Location so its own relative imports resolve, a deferred namespace evaluates its module instead of exposing uninitialized bindings, and an import abandoned by a global snapshot restore reports itself faulted instead of polling forever.

The process no longer dies for recoverable reasons. Options.LimitRecursion used to kill the host process for most useful limits — the constraint fired, and the unwind itself overflowed the stack; exception filters now let it unwind ~7× deeper. The new opt-in Options.Constraints.StackOverflowGuard converts unbounded recursion — reachable through eighteen distinct routes, new, accessors, coercions and Proxy traps included — from a process kill into a catchable RangeError, exempting strict tail calls, which grow no stack. And a family of CLR exceptions that escaped engine.Evaluate past every script catch are now proper JavaScript errors or correct results: sorting with an inconsistent comparator, destructuring with a function-valued default (const { onChange = () => {} } = opts), toLocaleString outside DateTime's range, typed-array defineProperty without a value, DataView reads at 2³¹, String.replace $' with a lying exec, and the first instant of year 10000.

New built-ins. Iterator.prototype.join, chunks, windows and includes; take/drop now throw RangeError for a finite limit above 2^53−1 per the updated proposals. Intl.Locale.prototype.getCollations reports CLDR-cited collation data that Intl.Collator accepts in full, a malformed collation option is a RangeError, and Intl.supportedValuesOf("collation") derives from the same lists so the three can never drift.

Conformance, from a review that ran what the suite does not. Two of the fixed defects had test262 coverage only under the never-generated staging/ directory, and several had none at all: parseInt strips the sign before testing for a hex prefix, so parseInt("-0x10") is −16; a suspended finally no longer swallows a pending break/continue; a Proxy (or exotic host object) as the global's prototype answers bare identifiers through its get trap; Date.prototype.toISOString emits the spec's six-digit expanded year and round-trips through Date.parse in every spelling including year 0; iterator helpers close their receiver exactly once and only when the spec says so, and carry their own @@​toStringTag; Map/Set size is the prototype accessor the spec defines rather than a phantom own property; a Proxy's defineProperty trap receives the partial descriptor the caller wrote; a string's @@​iterator is read once, with the primitive as receiver; Array.prototype.join re-asks the array when a side effect fills a hole mid-join; a direct eval reaches the enclosing function's arguments in both modes; and Temporal.Now drops the methods the proposal removed.

Embedder surface. OperationDeadlineConstraint bounds a whole multi-entry host operation; ScriptPreparationOptions.StaticAnalysis trades prepare-time analysis for per-engine materialization on shared graphs; ModuleFactory.LocationOf exposes the module-naming rule a host must match; Engine.Advanced.HostDefined carries per-request state on a pooled engine; the CLR exception behind an interop error is reachable through JintException.TryGetClrException with opt-in ChainClrExceptions(), and a host method's own TargetException is no longer mistaken for a receiver mismatch; and a recursion-limit failure propagates out of a module load instead of becoming a catchable rejection.

Performance, gated. Against v4.15.3 on idle hardware, medians of three paired runs: controlflow-recursive −15.6% time and −40.4% allocation (proper tail calls), bitops-3bit-bits-in-byte −8.9%, math-spectral-norm −7.3%, crypto-sha1 −6.9%, 3d-raytrace −5.9%, math-cordic −5.8%, with a broad −1–4% tail across the call- and string-heavy rows; no row moved outside its own measured cross-run envelope in the other direction, and allocation is flat within ±0.2% suite-wide. Warmed parseInt call sites take the frameless fast-call lane (−13% on the parse loop), joined by the Number predicates, String.prototype.indexOf/startsWith/endsWith/includes/at/substr, global isNaN/isFinite and Array.isArray (−3% to −19%) and the Map/Set method family (map.get hit loop −13%); existence questions on a wrapped dictionary answer from ContainsKey, taking in −33% with −98% allocation and Object.keys −37%; resolving an inherited global no longer allocates per miss (−99.99% on the read loop) and a global created through an inherited write keeps the in-place store; JSON replacer/reviver eligibility is decided once per document, built-in callback dispatch once per loop, a call site's arguments reach an interpreted callee in registers, and function-local let/const live in fixed slots.

Breaking changes. Int32Extensions/Int64Extensions/DoubleExtensions — polyfill hosts that leaked into the public API — are now internal; on net462/netstandard2.0, code with using Jint; may have bound span Parse/TryParse members through them. JsonParser rejects trailing commas. Number.parseInt.length/Number.parseFloat.length report their spec values. Post-construction mutation of an Options instance no longer reaches an already-built engine, and Options.Configure callbacks work again. UnwrapIfPromise reports a cancelled engine as ExecutionCanceledException instead of a timeout. Time-zone matching is ASCII-case-insensitive per ECMA-402.

On the engine comparison benchmarks, Jint 4.16.0 is the fastest engine outright on 5 of 12 scripts — leading dromaeo-object-regexp-modern over native V8 by 1.25× — in a statistical tie for first on interop-collection-traversal, the fastest managed engine on 10 of 12, the fastest interpreter on all 12, and 8.6×–11.2× ahead of ClearScript (native V8) on every interop row while allocating 3.9×–12.4× less than the nearest managed competitor.

What's Changed

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.Authentication.JwtBearer's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.DataProtection.EntityFrameworkCore from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.DataProtection.EntityFrameworkCore's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.OpenApi from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.OpenApi's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.TestHost from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.TestHost's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.CodeAnalysis.Analyzers from 5.6.0 to 5.9.0.

Release notes

Sourced from Microsoft.CodeAnalysis.Analyzers's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.CodeAnalysis.CSharp from 4.8.0 to 5.9.0.

Release notes

Sourced from Microsoft.CodeAnalysis.CSharp's releases.

5.0.4

Release

5.0.2

Release Notes
Install Instructions

Repos

5.0.1

Release Notes
Install Instructions

Repo

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.EntityFrameworkCore's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.Design from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.EntityFrameworkCore.Design's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.InMemory from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.EntityFrameworkCore.InMemory's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.Relational from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.EntityFrameworkCore.Relational's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Http.Resilience from 10.9.0 to 10.10.0.

Release notes

Sourced from Microsoft.Extensions.Http.Resilience's releases.

10.10.0

This month's release focuses on AI package reliability: closing gaps in evaluation scoring, hardening OpenAI image-option handling, and removing the deprecated OpenAI Assistants API support.

Experimental API Changes

Removed Experimental APIs

  • OpenAI Assistants experimental APIs removed (was experimental under OPENAI001) #​7724

What's Changed

AI

  • Remove OpenAI Assistants API support #​7724 by @​jozkee (co-authored by @​Copilot)
  • Update OpenAI package version to 2.13.0 #​7726 by @​jozkee
  • OpenAI: Avoid null implicit conversions for image options #​7727 by @​jozkee (co-authored by @​Copilot)

AI Evaluation

  • Fail closed when a quality metric has no valid score #​7735 by @​thaildhe172591
  • Validate path segments in Azure storage result store and response cache #​7718 by @​Lroca88

Repository Infrastructure Updates

  • Add TfxInstaller for publishing #​7695 by @​peterwaltonwork
  • Bump PowerShell from 7.6.4 to 7.6.5 #​7702
  • [Infrastructure] Update vulnerable npm dependencies #​7705 by @​wtgodbe
  • Add Node installation for TfxInstaller #​7703 by @​peterwaltonwork
  • Publish VSIX using publish task instead of output #​7711 by @​peterwaltonwork
  • Bump dotnet-coverage from 18.9.0 to 18.10.0 #​7708
  • Do not validate extension during publish step #​7725 by @​peterwaltonwork
  • Add skill for upgrading OpenAI #​7728 by @​jozkee
  • Fix source indexer stage #​7694 by @​jjonescz

Acknowledgements

  • @​Lroca88 made their first contribution in #​7718
  • @​thaildhe172591 made their first contribution in #​7735
  • @​ANcpLua submitted issue #​7665 (resolved by #​7735)
  • @​jeffhandley @​peterwald @​shyamnamboodiripad reviewed pull requests

Full Changelog: dotnet/extensions@v10.9.0...v10.10.0

Commits viewable in compare view.

Updated Microsoft.Extensions.TimeProvider.Testing from 10.9.0 to 10.10.0.

Release notes

Sourced from Microsoft.Extensions.TimeProvider.Testing's releases.

10.10.0

This month's release focuses on AI package reliability: closing gaps in evaluation scoring, hardening OpenAI image-option handling, and removing the deprecated OpenAI Assistants API support.

Experimental API Changes

Removed Experimental APIs

  • OpenAI Assistants experimental APIs removed (was experimental under OPENAI001) #​7724

What's Changed

AI

  • Remove OpenAI Assistants API support #​7724 by @​jozkee (co-authored by @​Copilot)
  • Update OpenAI package version to 2.13.0 #​7726 by @​jozkee
  • OpenAI: Avoid null implicit conversions for image options #​7727 by @​jozkee (co-authored by @​Copilot)

AI Evaluation

  • Fail closed when a quality metric has no valid score #​7735 by @​thaildhe172591
  • Validate path segments in Azure storage result store and response cache #​7718 by @​Lroca88

Repository Infrastructure Updates

  • Add TfxInstaller for publishing #​7695 by @​peterwaltonwork
  • Bump PowerShell from 7.6.4 to 7.6.5 #​7702
  • [Infrastructure] Update vulnerable npm dependencies #​7705 by @​wtgodbe
  • Add Node installation for TfxInstaller #​7703 by @​peterwaltonwork
  • Publish VSIX using publish task instead of output #​7711 by @​peterwaltonwork
  • Bump dotnet-coverage from 18.9.0 to 18.10.0 #​7708
  • Do not validate extension during publish step #​7725 by @​peterwaltonwork
  • Add skill for upgrading OpenAI #​7728 by @​jozkee
  • Fix source indexer stage #​7694 by @​jjonescz

Acknowledgements

  • @​Lroca88 made their first contribution in #​7718
  • @​thaildhe172591 made their first contribution in #​7735
  • @​ANcpLua submitted issue #​7665 (resolved by #​7735)
  • @​jeffhandley @​peterwald @​shyamnamboodiripad reviewed pull requests

Full Changelog: dotnet/extensions@v10.9.0...v10.10.0

Commits viewable in compare view.

Updated Microsoft.NET.Test.Sdk from 18.8.1 to 18.10.1.

Release notes

Sourced from Microsoft.NET.Test.Sdk's releases.

18.10.1

What's Changed

Full Changelog: microsoft/vstest@v18.10.0...v18.10.1

18.10.0

What's Changed

Full Changelog: microsoft/vstest@v18.9.0...v18.10.0

18.9.0

What's Changed

Description has been truncated

Bumps docfx from 2.78.5 to 2.81.0
Bumps Jint from 4.15.3 to 4.16.4
Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.DataProtection.EntityFrameworkCore from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.OpenApi from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.TestHost from 10.0.11 to 10.0.12
Bumps Microsoft.CodeAnalysis.Analyzers from 5.6.0 to 5.9.0
Bumps Microsoft.CodeAnalysis.CSharp from 4.8.0 to 5.9.0
Bumps Microsoft.EntityFrameworkCore from 10.0.11 to 10.0.12
Bumps Microsoft.EntityFrameworkCore.Design from 10.0.11 to 10.0.12
Bumps Microsoft.EntityFrameworkCore.InMemory from 10.0.11 to 10.0.12
Bumps Microsoft.EntityFrameworkCore.Relational from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.Http.Resilience from 10.9.0 to 10.10.0
Bumps Microsoft.Extensions.TimeProvider.Testing from 10.9.0 to 10.10.0
Bumps Microsoft.NET.Test.Sdk from 18.8.1 to 18.10.1
Bumps Microsoft.OpenApi to 2.12.0, 3.10.2
Bumps MinVer from 7.0.0 to 8.0.0
Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.17.0 to 1.19.1
Bumps OpenTelemetry.Extensions.Hosting from 1.17.0 to 1.19.1
Bumps OpenTelemetry.Instrumentation.AspNetCore from 1.17.0 to 1.19.0
Bumps OpenTelemetry.Instrumentation.Http from 1.17.0 to 1.19.0
Bumps Scalar.AspNetCore from 2.16.19 to 2.17.10
Bumps System.IdentityModel.Tokens.Jwt from 8.22.0 to 8.23.0
Bumps Testcontainers.PostgreSql from 4.13.0 to 4.15.0
Bumps xunit.runner.visualstudio from 3.1.5 to 4.0.0
Bumps Xunit.SkippableFact from 1.5.61 to 1.5.85

---
updated-dependencies:
- dependency-name: docfx
  dependency-version: 2.81.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: Jint
  dependency-version: 4.16.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.AspNetCore.DataProtection.EntityFrameworkCore
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.EntityFrameworkCore
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.AspNetCore.OpenApi
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.OpenApi
  dependency-version: 2.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: Microsoft.AspNetCore.TestHost
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.CodeAnalysis.Analyzers
  dependency-version: 5.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: Microsoft.CodeAnalysis.CSharp
  dependency-version: 5.9.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: nuget-all
- dependency-name: Microsoft.EntityFrameworkCore.Design
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.EntityFrameworkCore.Relational
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.EntityFrameworkCore.InMemory
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.Extensions.Http.Resilience
  dependency-version: 10.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: Microsoft.Extensions.TimeProvider.Testing
  dependency-version: 10.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.10.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: Microsoft.OpenApi
  dependency-version: 3.10.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: nuget-all
- dependency-name: MinVer
  dependency-version: 8.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: nuget-all
- dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: OpenTelemetry.Extensions.Hosting
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: OpenTelemetry.Instrumentation.AspNetCore
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: OpenTelemetry.Instrumentation.Http
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: Scalar.AspNetCore
  dependency-version: 2.17.10
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: System.IdentityModel.Tokens.Jwt
  dependency-version: 8.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: Testcontainers.PostgreSql
  dependency-version: 4.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: xunit.runner.visualstudio
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: nuget-all
- dependency-name: Xunit.SkippableFact
  dependency-version: 1.5.85
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Sep 27, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants