Skip to content

NuGet: Bump the wolverine group with 1 update - #1581

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/wolverine-680610959d
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/wolverine-680610959d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Updated WolverineFx.EntityFrameworkCore from 6.29.2 to 6.30.3.

Release notes

Sourced from WolverineFx.EntityFrameworkCore's releases.

6.30.3

Patch release. Requires JasperFx 2.57.1, which ships the code-generation half of two of these fixes.

Several of these failed silently — a host that started clean, passed health checks, and did less than it appeared to. Worth a look if any of the shapes below match your application.

Code generation and service location

  • ServiceProviderSource.IsolatedAndScoped is now honored by Wolverine.HTTP (#​4171). An endpoint or middleware asking for an IServiceProvider always received httpContext.RequestServices, whatever you configured. Note the consequence: asking for an IServiceProvider in an endpoint is service location and now registers as such, so under ServiceLocationPolicy.NotAllowed those endpoints will throw where they previously slipped past the policy unnoticed. Message handlers have always behaved this way.

  • Scope priming now fires for every chain that service-locates, not only those naming an IServiceProvider (#​4171). If a chain reached service location solely through an opaque scoped/transient registration, its child scope was never primed — so a service-located IMessageContext, IMessageBus, or Marten IDocumentSession was a second, un-enrolled instance rather than the one the handler already owned. Handlers and HTTP endpoints are both covered now.

  • Lazy<T> dependencies resolve through their registration (#​4159). An open-generic registration such as TryAddScoped(typeof(Lazy<>), typeof(LazyResolver<>)) was ignored whenever the closed type was itself concrete, and new Lazy<IFoo>() was emitted instead. That compiles and can never work — the first .Value throws MissingMemberException for any service without a public parameterless constructor. Relatedly, AlwaysUseServiceLocationFor(typeof(Lazy<>)) accepted an open generic and then matched nothing; it now matches that generic's closed forms.

Sagas

  • ResequencerSaga advances LastSequence when a message is handled, not when it is published (#​4172). A replayed message could let a queue backlog walk past the ordering guard while it was still in flight, reordering the handled sequence.

  • An already-sequenced arrival is observable and overridable (#​4175). A message whose order the saga had already passed was handled again in silence. The new shouldHandleAlreadySequenced hook logs a warning by default — behavior is unchanged — and can be overridden to discard, raise a metric, or throw.

Startup

  • AutoCreate.None no longer pays for a full schema diff at startup (#​4166).

Full changelog: JasperFx/wolverine@V6.30.2...V6.30.3

6.30.2

This addresses an issue encountered by a JasperFx client hitting a sudden crunch of messages being enqueued into local queues. Not something we expect to be common at all, but now we're better anyway!

What's Changed

Full Changelog: JasperFx/wolverine@V6.30.1...V6.30.2

6.30.1

There's some CritterWatch related functionality smuggled in here for our forthcoming Event Modeling visualization. Otherwise, this is mostly a ton of fine grained improvements for CI or message broker usage problems detected by dogfooding and some "Mr. AI tool, go try to identify potential problems" action

What's Changed

Full Changelog: JasperFx/wolverine@V6.30.0...V6.30.1

6.30.0

Wolverine 6.30.0 is a large release built around one headline feature — a new endpoint mode — plus the usual crop of transport fixes, and a couple of long-standing multi-tenancy and HTTP gaps closed.

EndpointMode.NativeAck

The main event. Buffered's throughput and partitioning with Inline's no-loss guarantee, and no database required.

A broker delivery is held unacknowledged while the envelope flows through an in-memory, optionally group-partitioned execution block, and is settled natively when the handler pipeline terminates. Nothing is acknowledged ahead of its handler, so work parked in a lane when a node goes away comes back rather than vanishing.

opts.ListenToRabbitQueue("orders")
    .ProcessInParallelWithNativeAcks();

The guarantee, stated exactly: no two messages sharing a group id execute concurrently. Ordering is per-slot best-effort, not per-group guaranteed; redelivery may reorder. Anything needing strict order under failure keeps the durable inbox.

Transport support is opt-in and default-closed — a transport must explicitly claim the mode, because most settlement models cannot express out-of-order completion. Adopted by RabbitMQ, Amazon SQS, Azure Service Bus, NATS JetStream, Redis Streams, Pulsar and GCP Pub/Sub (#​3708, #​4046, #​4047, #​4050, #​4051, #​4052, #​4053).

Supporting work in the same wave:

  • Lease renewal for queued envelopes on clocked transports — SQS, ASB, JetStream and Pub/Sub run a clock on an unsettled delivery, and the risk window is lane queue time plus handler time (#​4048).
  • In-memory idempotency guard, an opt-in duplicate filter for a mode with no inbox row to deduplicate against (#​3710).
  • Global partitioning across sharded queues (#​3709).
  • Listener mode coherence validation, which caught that RabbitMQ queues default to Inline — so sharded topologies were silently unpartitioned without an explicit BufferedInMemory() (#​3712, #​4022).
  • A five-node chaos reproduction under webhook flood, measuring the real duplicate rate on abrupt node loss (#​3713).

Multi-tenancy

  • Conjoined EF Core tenancy now works when Marten owns the message store via IntegrateWithWolverine(). Marten hands Wolverine an NpgsqlDataSource rather than a connection string, and NpgsqlDataSource.ConnectionString deliberately omits the password — so there is a new DbDataSource overload of AddDbContextWithWolverineManagedConjoinedTenancy that carries credentials through intact. A second defect on the same path is fixed too: IntegrateWithWolverine() never registered the tenant partitioning provider, so PartitionPerTenant() failed (#​4044).

HTTP and event sourcing

  • [StreamState] and [StreamEvents] — new parameter attributes for handlers whose read is the raw stream rather than the folded aggregate, for timeline and audit shaped endpoints that [ReadModel] cannot express. Store-agnostic across Marten, Polecat and Fisher; Marten batches both fetches into a single round trip (#​3627).
  • Marten concurrency conflicts as 409 — a documented, tested recipe for mapping optimistic-concurrency failures on [WriteAggregate] endpoints to ProblemDetails instead of an unhandled 500. Note that StreamLockedException derives from MartenException, not ConcurrencyException, so catching only the latter silently leaves FetchForExclusiveWriting returning 500s (#​3764).
  • Event Model slices per route — HttpChainDescriptor and GrpcRpcDescriptor now carry the slice the route is, so a consumer walking endpoint by endpoint sees it next to the route rather than only through the assembled model (#​4000).

Transport fixes

  • Pulsar: requeue, scheduled retry and dead-letter routing implemented (#​3797). A global failure rule was silently disabling every user error policy application-wide (#​4075). Hot-tail listeners silently dropped deferred messages in every mode (#​4060).
  • GCP Pub/Sub: listener shutdown could hang on in-flight callbacks (#​4065); exhausting MaxTotalAckExtension silently delivered a concurrent duplicate rather than reporting anything (#​4066); effective listener concurrency was not what the configuration implied, and the flow-control bound is global per SubscriberClient rather than per inner client (#​4067). PubsubTopicOptions.OrderBy gained a configuration surface (#​4087).
  • Redis: DeleteStreamEntryOnAck silently never acked on Redis < 8.2, where XACKDEL is unsupported (#​4058).
  • Ack reliability: a shared ack-attempt budget across stacked retry blocks, and terminal-failure classification for Azure Service Bus and SQS so a permanent settle failure stops rather than burning the whole budget (#​4012).

Upgrading

Additive. EndpointMode.NativeAck is opt-in per endpoint and default-closed per transport, and MaximumBrokerRedeliveries defaults to off. Requires JasperFx 2.55.0.

Commits viewable in compare view.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps WolverineFx.EntityFrameworkCore from 6.29.2 to 6.30.3

---
updated-dependencies:
- dependency-name: WolverineFx.EntityFrameworkCore
  dependency-version: 6.30.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: wolverine
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 4, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dotnet. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 4, 2026
@dependabot
dependabot Bot requested a review from foxminchan as a code owner September 4, 2026 03:41
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 4, 2026
@github-actions

github-actions Bot commented Sep 4, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA 5ad526a.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

Scanned Files

None

@netlify

netlify Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for bookwormdev canceled.

Name Link
🔨 Latest commit 5ad526a
🔍 Latest deploy log https://app.netlify.com/projects/bookwormdev/deploys/6a9a3df158b94f00085e3c24

@dependabot @github

dependabot Bot commented on behalf of github Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Looks like WolverineFx.EntityFrameworkCore is updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 11, 2026
@dependabot
dependabot Bot deleted the dependabot/nuget/wolverine-680610959d branch September 11, 2026 03:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants