Skip to content

chore: upgrade to .NET 10 - #93

Merged
hamzahalq merged 1 commit into
mainfrom
hamza/chore/dotnet10-upgrade
Sep 30, 2026
Merged

hamzahalq merged 1 commit into
mainfrom
hamza/chore/dotnet10-upgrade

Conversation

@hamzahalq

Copy link
Copy Markdown
Contributor

Retargets every project to net10.0 and publishes as 10.0.x (was 8.1.x), built with the .NET 10 SDK. PrimitiveTypes goes to 10.0.0, and the Microsoft.Extensions/AspNetCore packages go to 10.0.12. The test project's System.IdentityModel.Tokens.Jwt goes to 8.19.2, the minimum JwtBearer 10 needs.

The .NET 10 SDK also audits transitive packages, so it now flags Newtonsoft.Json 12.0.3 pulled in by the OCI SDK. That dependency isn't new.

.NET 8 consumers stay on 8.1.x.

Verified locally: build clean, LocalTests 16/16, all 10 packages pack as lib/net10.0. The S3/Azure/OCI/GCS tests need real credentials and fail the same way on main.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: simplify9/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 4bf4e601-371a-4977-94e0-09ba7cc19e72

📥 Commits

Reviewing files that changed from the base of the PR and between a917801 and ccaa1ee.

📒 Files selected for processing (18)
  • .github/workflows/nuget-publish.yml
  • CLAUDE.md
  • README.md
  • SW.CloudFiles.AS.Extensions/SW.CloudFiles.AS.Extensions.csproj
  • SW.CloudFiles.AS.UnitTest/SW.CloudFiles.AS.UnitTest.csproj
  • SW.CloudFiles.AS/SW.CloudFiles.AS.csproj
  • SW.CloudFiles.GC.Extensions/SW.CloudFiles.GC.Extensions.csproj
  • SW.CloudFiles.GC.UnitTests/SW.CloudFiles.GC.UnitTests.csproj
  • SW.CloudFiles.GC/SW.CloudFiles.GC.csproj
  • SW.CloudFiles.LocalTests.Extensions/SW.CloudFiles.LocalTests.Extensions.csproj
  • SW.CloudFiles.LocalTests.UnitTests/SW.CloudFiles.LocalTests.UnitTests.csproj
  • SW.CloudFiles.LocalTests/SW.CloudFiles.LocalTests.csproj
  • SW.CloudFiles.OC.Extensions/SW.CloudFiles.OC.Extensions.csproj
  • SW.CloudFiles.OC.UnitTest/SW.CloudFiles.OC.UnitTest.csproj
  • SW.CloudFiles.OC/SW.CloudFiles.OC.csproj
  • SW.CloudFiles.S3.Extensions/SW.CloudFiles.S3.Extensions.csproj
  • SW.CloudFiles.S3/SW.CloudFiles.S3.csproj
  • SW.CloudFiles.UnitTests/SW.CloudFiles.UnitTests.csproj

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
🧰 Additional context used
📓 Path-based instructions (1)
Treat GitHub Actions changes as supply-chain sensitive.

⚙️ CodeRabbit configuration file

Files:

  • .github/workflows/nuget-publish.yml
🔇 Additional comments (3)
.github/workflows/nuget-publish.yml (1)

31-33: LGTM!

CLAUDE.md (1)

7-7: LGTM!

README.md (1)

22-22: LGTM!

Also applies to: 427-427


📝 Summary

Summary

  • Retargets all projects to net10.0 and updates assembly versions to 10.0.0.0.
  • Updates the NuGet publish workflow to use .NET SDK 10.0.x and publish version 10.0.x.
  • Updates SimplyWorks.PrimitiveTypes to 10.0.0 and relevant Microsoft.Extensions and ASP.NET Core packages to 10.0.12.
  • Updates the test project’s System.IdentityModel.Tokens.Jwt dependency to 8.19.2.

Risk

risk:medium — This changes the target framework and package versions across all projects. Consumers and build environments must support .NET 10.

Security-sensitive areas

The test project updates JWT and JwtBearer dependencies. No authentication implementation changes are reported.

Test coverage impact

The reported validation is a clean build and LocalTests passing 16/16. Cloud-provider tests require credentials; the author reports that they fail the same way on main. These results are author-reported and were not independently verified.

Operational concerns

Update CI and release environments to use the .NET 10 SDK. The author reports that .NET 8 consumers remain on 8.1.x; confirm package publishing preserves that compatibility path. The author also reports an existing transitive Newtonsoft.Json 12.0.3 dependency from the OCI SDK. Review that dependency during the upgrade.

Walkthrough

The library and test projects now target .NET 10. Project assembly versions and selected package versions are updated. The NuGet publishing workflow and project documentation also specify .NET 10.

Changes

.NET 10 target upgrade

Layer / File(s) Summary
Library project targets and dependencies
SW.CloudFiles.AS/, SW.CloudFiles.GC/, SW.CloudFiles.LocalTests/, SW.CloudFiles.OC/, SW.CloudFiles.S3/, SW.CloudFiles.*.Extensions/
Library projects now target .NET 10 and set assembly version 10.0.0.0. Selected projects update SimplyWorks.PrimitiveTypes to 10.0.0; the OC project also updates Microsoft.Extensions.Logging to 10.0.12.
Test project targets and packages
SW.CloudFiles.AS.UnitTest/, SW.CloudFiles.GC.UnitTests/, SW.CloudFiles.LocalTests.UnitTests/, SW.CloudFiles.OC.UnitTest/, SW.CloudFiles.UnitTests/
Test projects now target .NET 10 and set assembly version 10.0.0.0. Selected ASP.NET Core testing packages change to 10.0.12; the main unit-test project also updates JWT to 8.19.2.
Publishing and framework documentation
.github/workflows/nuget-publish.yml, CLAUDE.md, README.md
The publishing workflow selects .NET SDK 10.0.x and package version 10.0. The documentation identifies .NET 10 as the target and minimum requirement.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Other

Suggested labels: security, infra, risk:high

Suggested reviewers: samerzughul

Merge Risk: ⚪ Minimal · up to ccaa1

Libraries and tests move to .NET 10, and publishing selects the .NET 10 SDK. No actionable merge-blocking risk remains in the reviewed changes.

Security Architecture Review

Security architecture risk: 🔵 Low · up to ccaa1

The runtime targets, release versions, and documented requirements advance together. No publishing-authority expansion or new security issue was established. Release recovery behavior and the security effects of upgraded dependencies remain incompletely verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The changed baseline reaches all ten published library and extension packages and consumers adopting their 10.0 line. Existing publishing authority remains relevant to package integrity, but the inspected caller shows no expansion of that authority. Credential scope and feed-side exposure cannot be determined from the caller alone.

Trust Boundaries and Controls

  • observed — The caller passes the existing NuGet credential to simplify9/.github/.github/workflows/reusable-nuget-publish.yml@main and retains contents:write, packages:write, and security-events:read permissions. This external code and credential trust boundary is unchanged by the PR; its effective implementation was unavailable for inspection.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: upgrading the projects to .NET 10.
Description check ✅ Passed The description directly explains the .NET 10 retargeting, package updates, publication changes, and reported validation.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hamzahalq
hamzahalq merged commit ef7a468 into main Sep 30, 2026
5 checks passed
@hamzahalq
hamzahalq deleted the hamza/chore/dotnet10-upgrade branch September 30, 2026 12:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants