Skip to content

chore: upgrade to .NET 10 - #138

Merged
hamzahalq merged 1 commit into
mainfrom
hamza/chore/dotnet10-upgrade
Sep 30, 2026
Merged

hamzahalq merged 1 commit into
mainfrom
hamza/chore/dotnet10-upgrade

Conversation

@hamzahalq

Copy link
Copy Markdown
Contributor

Retargets every project to net10.0 (Desktop: net10.0-windows) and publishes as 10.0.x (was 8.1.x), built with the .NET 10 SDK. PrimitiveTypes and CloudFiles go to 10.0.0, and the Microsoft.Extensions/AspNetCore packages go to 10.0.12. The sample host's hard-coded bin/.../net8.0 adapter path becomes net10.0.

Merge after simplify9/SW-CloudFiles#93 has published 10.0.0. Until then, restore fails on the CloudFiles references.

Adapters built on Sdk 10.x need the .NET 10 runtime. Existing net6/net8 adapters keep working on their current Sdk versions.

Verified locally against a local CloudFiles 10 build: build clean, unit tests 86/86 (incl. adapter subprocess tests against RabbitMQ), installer tests 15/15, all 3 packages pack as lib/net10.0.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: simplify9/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 358d87c5-5252-4aa5-a634-3457214aa952

📥 Commits

Reviewing files that changed from the base of the PR and between 1da9d83 and 799d1ae.

📒 Files selected for processing (22)
  • .github/workflows/nuget-publish.yml
  • SW.Serverless.Contract/SW.Serverless.Contract.csproj
  • SW.Serverless.Desktop/SW.Serverless.Desktop.csproj
  • SW.Serverless.Installer.UnitTests/SW.Serverless.Installer.UnitTests.csproj
  • SW.Serverless.Installer/SW.Serverless.Installer.csproj
  • SW.Serverless.SampleWeb/SW.Serverless.SampleWeb.csproj
  • SW.Serverless.Samples.Carrier/SW.Serverless.Samples.Carrier.csproj
  • SW.Serverless.Samples.CarrierContract/SW.Serverless.Samples.CarrierContract.csproj
  • SW.Serverless.Samples.Classic/SW.Serverless.Samples.Classic.csproj
  • SW.Serverless.Samples.FolderSource/SW.Serverless.Samples.FolderSource.csproj
  • SW.Serverless.Samples.Greedy/SW.Serverless.Samples.Greedy.csproj
  • SW.Serverless.Samples.Host/Program.cs
  • SW.Serverless.Samples.Host/SW.Serverless.Samples.Host.csproj
  • SW.Serverless.Samples.LargeFiles/SW.Serverless.Samples.LargeFiles.csproj
  • SW.Serverless.Samples.RabbitConsumer/SW.Serverless.Samples.RabbitConsumer.csproj
  • SW.Serverless.Samples.RabbitMq/SW.Serverless.Samples.RabbitMq.csproj
  • SW.Serverless.Samples.RabbitPublisher/SW.Serverless.Samples.RabbitPublisher.csproj
  • SW.Serverless.Samples.Ticker/SW.Serverless.Samples.Ticker.csproj
  • SW.Serverless.Sdk/SW.Serverless.Sdk.csproj
  • SW.Serverless.UnitTests.Adapter/SW.Serverless.UnitTests.Adapter.csproj
  • SW.Serverless.UnitTests/SW.Serverless.UnitTests.csproj
  • SW.Serverless/SW.Serverless.csproj

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (1)
  • GitHub Check: vuln-gate / check
🧰 Additional context used
📓 Path-based instructions (1)
Treat GitHub Actions changes as supply-chain sensitive.

⚙️ CodeRabbit configuration file

Files:

  • .github/workflows/nuget-publish.yml

📝 Summary
  • Retargeted the projects and publish workflow to .NET 10. Updated package versions, including CloudFiles and PrimitiveTypes to 10.0.0 and Microsoft.Extensions/AspNetCore packages to 10.0.12. Updated the sample host to locate net10.0 outputs.
  • Risk: risk:medium. This is a broad framework and dependency upgrade. Restore depends on CloudFiles 10.0.0 being published.
  • Security-sensitive areas: No security-specific code changes are described. Dependency versions changed; assess them through the normal dependency and supply-chain review.
  • Test coverage impact: The author reports a local build and 86/86 unit tests plus 15/15 installer tests, using a local CloudFiles 10 build. These results are author-reported, not independently verified. Restore may fail until the CloudFiles package is available.
  • Operational concerns: Merge after CloudFiles 10.0.0 is published. Adapters built with SDK 10.x require the .NET 10 runtime; existing net6/net8 adapters continue to use their current SDK versions.

Walkthrough

Projects across the solution now target .NET 10. Selected package references, sample assembly lookup, and the NuGet publish workflow are updated to use .NET 10 version values.

Changes

.NET 10 Migration

Layer / File(s) Summary
Project targets and package versions
SW.Serverless.Contract/*.csproj, SW.Serverless.Desktop/*.csproj, SW.Serverless.Installer*/*.csproj, SW.Serverless.SampleWeb/*.csproj, SW.Serverless.Sdk/*.csproj, SW.Serverless.UnitTests*/*.csproj, SW.Serverless/SW.Serverless.csproj
These projects now target .NET 10. Selected SimplyWorks packages and Microsoft.Extensions packages are upgraded; Microsoft.AspNetCore.Mvc.Testing changes to 10.0.12. The gRPC client remains at 2.66.0.
Sample and publish alignment
SW.Serverless.Samples.*/*.csproj, SW.Serverless.Samples.Host/Program.cs, .github/workflows/nuget-publish.yml
Sample projects now target .NET 10. The sample host searches the net10.0 output directory. The NuGet workflow inputs change to version 10.0 and SDK 10.0.x.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Suggested labels: infra, risk:high

Suggested reviewers: samerzughul

Merge Risk: 🟡 Moderate · up to 799d1

Do not merge until CloudFiles 10.0.0 is available from the configured feeds, otherwise affected projects may not restore or build.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 799d1

The visible changes do not expand publishing privileges or adapter authority. The main uncertainty is coordinating dependency publication and compatible runtime installation: CloudFiles 10.0.0 availability and mixed-runtime deployment and rollback have not been independently established.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The security-relevant exposure is the runtime and dependency code executed by adopting hosts, adapters, and installer deployments. CloudFiles dependencies operate with installer-supplied storage credentials and destinations. The affected tenants, assets, environments, and effective storage permissions cannot be quantified without deployment configuration and external package behavior.

Trust Boundaries and Controls

  • observed — The existing host-to-adapter boundary uses a process launch without shell execution and delivers the attachment token through stdin rather than argv. Attachment rejects unrecognized tokens. These controls do not establish an OS sandbox or prevent inherited environment access, and their source is unchanged in the inspected migration revision.
  • observed — The installer continues to obtain credentials and storage destinations from CLI options or a CloudFiles configuration file and pass them to its upload path. No new credential source is visible. Whether CloudFiles 10.0.0 changes credential handling, endpoint validation, or provider authorization semantics remains unverified.

Resilience and Maintainability Implications

  • observed — Exclusive startup is serialized per adapter and instance key and reuses a Ready instance. New launches receive fresh tokens, and inspected startup failures remove pending attachment authority. These are existing ownership and recovery controls; deployment rollback and all concurrent restart or interruption outcomes remain outside the established coverage.

Hardening Proposals

  • proposed — Before rollout, confirm required CloudFiles versions are available from the intended feed, establish the compatible runtimes required by deployed adapters, and document recovery from partial publication or deployment. Preserve legacy runtimes where older adapters still require them rather than treating the host upgrade as proof of adapter compatibility.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the primary change: upgrading the project to .NET 10.
Description check ✅ Passed The description directly covers the .NET 10 retargeting, dependency updates, SDK changes, adapter path update, dependency timing, and test results.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (21 skipped: 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hamzahalq
hamzahalq merged commit c97ae0a into main Sep 30, 2026
5 checks passed
@hamzahalq
hamzahalq deleted the hamza/chore/dotnet10-upgrade branch September 30, 2026 13:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants