Skip to content

Bump Aspire.Hosting.Testing from 13.4.4 to 13.4.5#573

Merged
Kiryuumaru merged 1 commit into
masterfrom
dependabot/nuget/RestfulHelpers.Test/RestfulHelpers.Test.UnitTest/master/Aspire.Hosting.Testing-13.4.5
Jun 17, 2026
Merged

Bump Aspire.Hosting.Testing from 13.4.4 to 13.4.5#573
Kiryuumaru merged 1 commit into
masterfrom
dependabot/nuget/RestfulHelpers.Test/RestfulHelpers.Test.UnitTest/master/Aspire.Hosting.Testing-13.4.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 17, 2026

Copy link
Copy Markdown
Contributor

Updated Aspire.Hosting.Testing from 13.4.4 to 13.4.5.

Release notes

Sourced from Aspire.Hosting.Testing's releases.

13.4.5

What's New in Aspire 13.4.5

Patch release for Aspire 13.4 clearing a transitive MessagePack security advisory, tightening CLI validation for Playwright configuration, and adding coding-agent detection to CLI telemetry.

🐛 Fixes

  • 🛡️ Bumped StreamJsonRpc to 2.25.29 to clear the MessagePack GHSA-hv8m-jj95-wg3x (CVE-2026-48109) NU1903 advisory — The transitive MessagePack 2.5.192 dependency pulled in via StreamJsonRpc 2.22.23 fell within the advisory's vulnerable LZ4 decompression range. Aspire does not use MessagePackFormatter or LZ4 — all StreamJsonRpc calls use SystemTextJsonFormatter over local Unix sockets — so the vulnerability was not reachable in practice. The bump clears the NU1903 warning for consumers of the Aspire.Hosting package. (#​18204, @​mitchdenny)
  • 🎭 playwrightCliVersion values that are not valid SemVer 2.0 now fail fast with a clear diagnostic — Previously an invalid override (range expression, dist-tag like latest, or a v-prefixed string) would surface as a generic npm resolution failure. The value is now validated with strict SemVer parsing at startup; an error naming the configuration key and the offending value is emitted immediately. (#​18205, @​mitchdenny)
  • 🤖 CLI telemetry now detects and reports the calling coding agent — When the Aspire CLI is invoked from inside a known coding agent environment (GitHub Copilot CLI, VS Code Copilot agent, etc.) the agent name is included in the main CLI telemetry event. GitHub Copilot CLI is specifically identified as copilot-cli. (#​18240, @​damianedwards)

🏷️ Housekeeping

  • 📄 Refreshed the @​microsoft/aspire-cli npm package README to be TypeScript-only — updated examples to the current ts-starter template (apphost.mts / aspire.mjs), added a backing-services snippet showing aspire add for PostgreSQL and Redis, and documented aspire dashboard run as a standalone dashboard option. (#​18221, @​adamint)

Full Changelog: v13.4.4...v13.4.5

Full commit: 73114e86c64aeb9f3f3c7da8e37df1ae4281b27e

Generated by Generate release notes for a new stable Aspire release · ● 4.4M

Commits viewable in compare view.

@dependabot dependabot Bot added .NET Pull requests that update .net code dependencies Pull requests that update a dependency file labels Jun 17, 2026
@Kiryuumaru Kiryuumaru enabled auto-merge (squash) June 17, 2026 19:25
---
updated-dependencies:
- dependency-name: Aspire.Hosting.Testing
  dependency-version: 13.4.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/nuget/RestfulHelpers.Test/RestfulHelpers.Test.UnitTest/master/Aspire.Hosting.Testing-13.4.5 branch from 6d08c95 to 10038cb Compare June 17, 2026 19:32
@Kiryuumaru Kiryuumaru merged commit 12a599d into master Jun 17, 2026
6 checks passed
@Kiryuumaru Kiryuumaru deleted the dependabot/nuget/RestfulHelpers.Test/RestfulHelpers.Test.UnitTest/master/Aspire.Hosting.Testing-13.4.5 branch June 17, 2026 19:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .net code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant