Skip to content

Bump coverlet.collector and 5 others - #10

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/dotnet-dependencies-b1b855473b
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/dotnet-dependencies-b1b855473b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Updated coverlet.collector from 10.0.1 to 10.1.0.

Release notes

Sourced from coverlet.collector's releases.

10.1.0

Improvements

  • Publish Microsoft.Testing.Platform coverage messages from coverlet.MTP #​2019
  • Implement dynamic exclusion filters for assemblies (Coverlet.MTP) #​1946
  • Replace legacy .sln files with modern .slnx format #​1966
  • coverlet.console: add trace diagnostics and actionable warnings for instrumentation/hit/empty-result failures #​2005
  • Relax auto-property skip logic and improve coverage for records #​1941

Fixed

  • Fix coverlet.MTP does not collect coverage on the .NET Framework portion of a large project #​1980 #​1967
  • Fix Regression in branch coverage for lambda expressions #​1938
  • Fix When using "is" with "or" in pattern matching, branch coverage is lower than normal #​1979
  • Fix silent zero coverage on .NET Framework since 8.0.0 #​1985 by @​tobiwae
  • Fix Race condition between ProcessExit hit-file write and out-of-proc coverage read causes EndOfStreamException #​1987 #​1988 by @​bkoelman
  • Fix Regression TypeInitializationException when targeting .NET Framework - Could not load type 'System.Collections.Concurrent.ConcurrentBag #​2010
  • Fix use --config-file CLI arg in coverlet.MTP #​2030 by alexthornton1
  • Fix silently empty coverage for shared-framework assemblies missing from compileLibraries #​2032 by @​Eljees

Diff between 10.0.1 and 10.1.0

Commits viewable in compare view.

Updated coverlet.msbuild from 10.0.1 to 10.1.0.

Release notes

Sourced from coverlet.msbuild's releases.

10.1.0

Improvements

  • Publish Microsoft.Testing.Platform coverage messages from coverlet.MTP #​2019
  • Implement dynamic exclusion filters for assemblies (Coverlet.MTP) #​1946
  • Replace legacy .sln files with modern .slnx format #​1966
  • coverlet.console: add trace diagnostics and actionable warnings for instrumentation/hit/empty-result failures #​2005
  • Relax auto-property skip logic and improve coverage for records #​1941

Fixed

  • Fix coverlet.MTP does not collect coverage on the .NET Framework portion of a large project #​1980 #​1967
  • Fix Regression in branch coverage for lambda expressions #​1938
  • Fix When using "is" with "or" in pattern matching, branch coverage is lower than normal #​1979
  • Fix silent zero coverage on .NET Framework since 8.0.0 #​1985 by @​tobiwae
  • Fix Race condition between ProcessExit hit-file write and out-of-proc coverage read causes EndOfStreamException #​1987 #​1988 by @​bkoelman
  • Fix Regression TypeInitializationException when targeting .NET Framework - Could not load type 'System.Collections.Concurrent.ConcurrentBag #​2010
  • Fix use --config-file CLI arg in coverlet.MTP #​2030 by alexthornton1
  • Fix silently empty coverage for shared-framework assemblies missing from compileLibraries #​2032 by @​Eljees

Diff between 10.0.1 and 10.1.0

Commits viewable in compare view.

Updated Microsoft.Agents.AI from 1.22.0 to 1.23.0.

Release notes

Sourced from Microsoft.Agents.AI's releases.

1.23.0

Changes:

  • be01deccaf3dd7b85e03620145bc1a757c857827 .NET: Add origin pinning to Foundry toolbox MCP client (#​8721)
  • 0d6d2bb6b0b58f3aabdf170320ab90fc300d4c99 .NET: fix: declarative workflow http variables (#​8797)
  • 2024d4df4c4dd01b904fb9daaf56f5759801654a .NET: Fix workflow topology edge multiplicity comparison (#​8656)
  • 37ce872a85fed62cedfd7fffa2e0bd43f7d32b92 .NET: Store created external input messages (#​8606)
  • 1370903bd8e6eb8871781cd1fcc74f674c022e0b .NET: [BREAKING] Better support tool changes between runs (#​8754)
See More
  • 3f1f3b50b57ccabe7725f8a60539622d5f1ca7b4 .NET: Propagate TextSearchProvider caller cancellation (#​8796)
  • 238d7e2e9bb9b469be172460e612c89840aad1cc .NET: Validate Foundry client headers before transport (#​8715)
  • c804f32c983df56bacc9a8698fde9d50edc2df3e .NET: [BREAKING] Bump Azure.AI.Projects to 3.0.0-beta.3, OpenAI to 2.14.0, and MEAI to 10.10.1 (#​8730) [ dotnet/extensions#​7760, dotnet/extensions#​7761 ]
  • 93cf98a042c0f4eb8e1e180beeab9474bcd96811 .NET: Update AGUI SDK packages to 1.0.0 (#​8769)
  • 109234952ad417b0e9368beed633e438eb2e389d Clarify CodeAct guest packages and host network access (#​8781)
  • 6f1522a50b66f117da34cc25ea299ba24a528b15 Temporarily skip OpenAI integration tests while the CI API key is invalid (#​8767)
  • 2c46deb91e70ea6d7bbc99263147e0f470d52546 .NET: Clarify hosting authentication, authorization, and isolation guidance (#​8677)
  • 024dd9908bc19fa42f070cfaf7c3775c2b17f09b .NET/Python: Improve MCP skill resource validation (#​8690)
  • 8ff549d3f7219bac0a405621616ed72090ba13b9 .NET: Correct InvokeAzureAgent response output (#​8605)
  • 5ee3e87d6768eadb7c4cf91507659a6069850692 .NET: Remove redundant NuGet configuration (#​8719)
  • 622737258c73f730adca5130b7b82fbc03ff8838 Set better expecations for contributors (#​8706)
  • 30b9b8e06766b2038e366d32979357c2fc4b9def .NET: Only consume stored approval state when the run succeeds (#​8692)
  • 834eb7ff12c83aadee56d468e3b01b4f0fc4084c fix(dotnet): persist function results as user messages (#​8655)
  • 0bbb7245d408b6b7209eca58609ca53a52a66cec .NET: [BREAKING] fix: use allow list for configuration keys (#​8200)
  • a638ce136ed6e0457877373b0e377e1f1d33277d .NET: Fix forwarded request-port type validation (#​8657)
  • 76ccf3c44cee748aa582c446a7218f91289f2aac fix(dotnet): forward declarative Azure agent version (#​8658)
  • 11b8b80a2c904a36603c4445df5ddb07a55e6817 Use review App permissions for repair reactions (#​8669)
  • 74e8fe6da942ee991819ea861de1841243d7c0e1 Use the workflow token for fix-ci evidence (#​8667)
  • 173978ee93e0ffa5ef4ebdbfe2e94cd6f8e8a996 .NET: Add function replace support for function middleware (#​8615)
  • bf93c539d247a9df6f66055b711a3015438c8dce .NET: [BREAKING] Enforce approval response binding consistently (#​8641)
  • 646e116a4099a6dc0f689ff2dd8b41b31ba2bdae .NET: [BREAKING] Fix DevUI approval continuation (#​8423) [ #​6006 ]
  • 925f4f2c6c494eba2779f7f79de1ca95958f6d8a .NET: ci/dotnet vscode configuration (#​8537)
  • ec7114ffc8656a9b5c56be252f0411d22887c896 .NET: fix: a bug where invoke function tool could bypass approval (#​8403)
  • c5a8c8d37d7cf15b493fb838084f4954be6b0223 fix(core): distinguish absent tool call arguments from parse failures (#​8609)
  • 17b349f2150d5b90649998a32a067db07319649a docs(core): fix positional invocations in detect_media_type_from_base64 docstrings (#​8614)
  • eb74c8cceba97bc037413dcf25cfcf1aeab77634 fix(core): ensure add_usage_details returns copies and filters non-ints consistently (#​8613)
  • 02bd1ba1de43ca8d1206a5c61e86ffc0d6f44b12 fix(ag-ui): allow text events when response_format is a json schema dictionary (#​8604)
  • 7b626709dbce2c170030c388cea9e611738e5be5 ci: removes workflow based PR limit to use GitHub native feature (#​8603)
  • bb53fe15a8375426a98763bd43eed64762af3f07 test(ollama): narrow pytest.raises blocks to wrap only get_response in error tests (#​8611)
  • 894b0f6f0bd2d59202ef04d5898302e05cbb7264 samples: add McpDocsResearch declarative workflow showcasing agent-level MCP pattern (#​6054)
  • 42c22c001761340f47b279e89a4e06aedb5549d9 Bump GitHub.Copilot.SDK to 1.0.1 and forward session config properties (incl. per-session GitHubToken) (#​5735) [ #​6381 ]

This list of changes was auto generated.

Commits viewable in compare view.

Updated SkiaSharp from 4.151.2 to 4.153.1.

Updated SkiaSharp.NativeAssets.Linux.NoDependencies from 4.151.2 to 4.153.1.

Updated SonarAnalyzer.CSharp from 10.34.0.3385 to 10.35.0.4138.

Release notes

Sourced from SonarAnalyzer.CSharp's releases.

10.35.0.4138

Release notes - .NET Analyzers - 10.35

Feature

NET-1313 Improve S3267: Suggest other LINQ methods instead of always Where
NET-4549 Update RSPEC before 10.35 release

False Positive

NET-87 Fix S6667 FP: Add an exception when rethrowing the exception
NET-1559 Fix S6966 FP: FluentValidation ValidateAndThrow should not be proposed
NET-3964 Fix S125 FP: Do not raise on comments that resemble code but are not
NET-4294 Fix S107 FP: Should not raise on constructors of dependency-injection managed types
NET-4310 Fix S8747 FP: Do not raise when data is backfilled via UpdateData
NET-4315 Fix S3453 FP: Should not raise on classes with static members and non-static nested types
NET-4415 Fix S8969 FP: redundant null-forgiving operator raised on ref-loop variables reassigned each iteration
NET-4466 Fix S6966 FP: Do not suggest a non-awaitable overload resolved via speculative rebind
NET-4546 Fix S6669 FP: overridden "format" rule parameter is ignored
NET-4556 Fix S1128 FP: SafeVisit abort silently drops necessary usings
NET-4634 Fix S9022 FP: Generic identity pass-through wrapper not implementing IEnumerable misclassified as a reshaping boundary
NET-4639 Fix S8717 FP: EF6 and EF Core referenced in the same compilation (in-progress migration)

False Negative

NET-4256 Fix S9022 FN: Include on owned-type navigation not detected as redundant
NET-4532 Fix S9022/S9023 FN: rule stays silent when the Include is used in a comparison, cast, or other common expression
NET-4541 Fix S5542 FN: Detect weak RSA signature padding

Bug

NET-4571 Fix AD0001: NRE in DoNotOverwriteCollectionElements
NET-4587 Fix AD0001: ArgumentNullException in ReleaseCorrectReaderWriterLockBase (S7131)
NET-4588 Fix AD0001: ArgumentNullException in FirstSingleShouldBeUsedOnNonEmptyCollectionBase (S7130)
NET-4636 Fix S6966 AD0001: NullReferenceException on null-conditional calls followed by an indexer

Maintenance

NET-4370 Drop backward compatibility with S4NET below 5.2
NET-4540 Update MSTest to 4.4.0
NET-4550 Bump version to 10.35
NET-4555 Update SonarSource/sonar-scanner-engine monorepo to v13.11.0.5929
NET-4558 Create SLCORE ticket instead of SLVSCODE and SLI on release
NET-4579 ShimLayer Generator: Remove old BasicBlock and ControlFlowBranch
NET-4580 Update dependency Microsoft.NET.Test.Sdk to 18.10.0
NET-4596 Update dependency org.codehaus.mojo:build-helper-maven-plugin to v3.6.2
NET-4597 Update dependency Verify.MSTest to 32.0.1
NET-4622 Update SonarSource/sonar-scanner-engine monorepo to v13.13.0.6016
NET-4628 Update dependency Microsoft.NET.Test.Sdk to 18.10.1
NET-4631 Update MSTest to 4.4.1
NET-4632 Harden S1144: internal-type usage scan no longer trusts partial SafeVisit walks
NET-4637 Update protocolbuffers/protobuf monorepo to v4.36.2
NET-4663 Restore sonar-csharp-enterprise-plugin minsize to 6200000

Commits viewable in compare view.

@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Sep 30, 2026
@dependabot dependabot Bot changed the title Bump the dotnet-dependencies group with 6 updates Bump coverlet.collector and 5 others Sep 30, 2026
@dependabot
dependabot Bot force-pushed the dependabot/nuget/dotnet-dependencies-b1b855473b branch 2 times, most recently from 60425bc to 204df9a Compare September 30, 2026 20:52
Bumps coverlet.collector from 10.0.1 to 10.1.0
Bumps coverlet.msbuild from 10.0.1 to 10.1.0
Bumps Microsoft.Agents.AI from 1.22.0 to 1.23.0
Bumps SkiaSharp from 4.151.2 to 4.153.1
Bumps SkiaSharp.NativeAssets.Linux.NoDependencies from 4.151.2 to 4.153.1
Bumps SonarAnalyzer.CSharp from 10.34.0.3385 to 10.35.0.4138

---
updated-dependencies:
- dependency-name: coverlet.collector
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-dependencies
- dependency-name: coverlet.msbuild
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-dependencies
- dependency-name: Microsoft.Agents.AI
  dependency-version: 1.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-dependencies
- dependency-name: SkiaSharp
  dependency-version: 4.153.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-dependencies
- dependency-name: SkiaSharp.NativeAssets.Linux.NoDependencies
  dependency-version: 4.153.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-dependencies
- dependency-name: SonarAnalyzer.CSharp
  dependency-version: 10.35.0.4138
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/nuget/dotnet-dependencies-b1b855473b branch from 204df9a to 49df6c2 Compare October 1, 2026 12:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants