Skip to content

chore(deps): update .NET dependencies - #145

Closed
deniswsrosa wants to merge 2 commits into
mainfrom
chore/dependency-update-20260706-depupdate-20260703T172451Z
Closed

deniswsrosa wants to merge 2 commits into
mainfrom
chore/dependency-update-20260706-depupdate-20260703T172451Z

Conversation

@deniswsrosa

@deniswsrosa deniswsrosa commented Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Updates direct NuGet dependencies for the ASP.NET quickstart while preserving the existing .NET 8 target and NuGet workflow.

Updated dependencies

Ecosystem Dependency Previous Updated Type Notes
NuGet BCrypt.Net-Next 4.1.0 4.2.0 Direct runtime Latest stable
NuGet Couchbase.Extensions.DependencyInjection 3.9.1 3.9.3 Direct runtime Latest stable
NuGet CouchbaseNetClient 3.9.1 3.9.3 Direct runtime Latest stable
NuGet Swashbuckle.AspNetCore 6.5.0 10.2.3 Direct runtime Latest stable; required OpenAPI namespace update
NuGet Swashbuckle.AspNetCore.Annotations 8.1.1 10.2.3 Direct runtime Latest stable
NuGet coverlet.collector 6.0.4 10.0.1 Direct test Latest stable
NuGet coverlet.msbuild 6.0.4 10.0.1 Direct test Latest stable
NuGet Microsoft.AspNetCore.Mvc.Testing 8.0.15 8.0.22 Direct test Latest compatible with net8.0; 10.0.9 requires net10.0
NuGet Microsoft.NET.Test.Sdk 17.11.1 18.7.0 Direct test Latest stable
NuGet xunit.runner.visualstudio 2.8.2 3.1.5 Direct test Latest stable
GitHub Actions ravsamhq/notify-slack-action v1 2.5.0 Direct CI action Fixes CI Report Status runtime failure observed after PR opened

Validation

  • Restore passed
  • Build passed
  • Integration tests passed against local Couchbase with travel-sample loaded
  • Swagger/OpenAPI JSON rendered
  • Swagger UI rendered in browser

Commands run:

dotnet restore Org.Quickstart.sln
dotnet build Org.Quickstart.sln --configuration Debug --no-restore
DB_CONN_STR=<local Couchbase> DB_USERNAME=<local admin> DB_PASSWORD=<local password> \
  dotnet test src/Org.Quickstart.IntegrationTests/Org.Quickstart.IntegrationTests.csproj \
  --configuration Debug --no-build --verbosity normal
curl http://127.0.0.1:8080/swagger/v1/swagger.json

Validation result: 35 integration tests passed locally.

Evidence

Check Result
dotnet list package --outdated before update Direct updates identified
Restore/build/test Passed locally with .NET 8 SDK
Swagger JSON /swagger/v1/swagger.json returned OpenAPI 3.0.4 with 7 paths
Swagger UI Browser rendered the API groups and schemas

Risk notes

  • Swashbuckle.AspNetCore 10.x uses Microsoft.OpenApi instead of Microsoft.OpenApi.Models; Program.cs was updated accordingly.
  • CI initially failed in ravsamhq/notify-slack-action@v1 after the build/test step had status success; the workflow action was updated to the maintained Node20-based 2.5.0 release.
  • Microsoft.AspNetCore.Mvc.Testing was held to 8.0.22 because the latest 10.0.9 package targets net10.0 and is incompatible with this repository's net8.0 target.
  • There are existing Dependabot PRs for subsets of these updates; this PR consolidates the validated direct dependency update set.

Rollback

Revert this PR to restore the previous NuGet package versions and OpenAPI namespace import.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates several NuGet package dependencies across the API and Integration Tests projects, and adjusts a namespace import in Program.cs. Feedback recommends removing the redundant Couchbase.Transactions package reference, as transactions are already integrated into the updated CouchbaseNetClient, and removing coverlet.msbuild to prevent potential conflicts with coverlet.collector.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

<PackageReference Include="Swashbuckle.AspNetCore.Annotations" Version="8.1.1" />
<PackageReference Include="Swashbuckle.AspNetCore" Version="10.2.3" />
<PackageReference Include="BCrypt.Net-Next" Version="4.2.0" />
<PackageReference Include="CouchbaseNetClient" Version="3.9.3" />

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Since CouchbaseNetClient is updated to version 3.9.3, the separate Couchbase.Transactions package (currently referenced on line 13) is deprecated and completely redundant. Transactions have been fully integrated into the core CouchbaseNetClient package since version 3.4.0. You can safely remove the Couchbase.Transactions package reference from this project.

- name: Report Status
if: always()
uses: ravsamhq/notify-slack-action@v1
uses: ravsamhq/notify-slack-action@2.5.0

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this the latest version available?

@ejscribner

Copy link
Copy Markdown
Contributor

@dex-the-ai is this PR still relevant and needed or did #146 cover it?

@dex-the-ai

Copy link
Copy Markdown
Contributor

@ejscribner #145 is still relevant. #146 didn't cover it.

What #146 changed (merged 2026-09-02):

  • README.md: documented the DB_CONN_STR / DB_USERNAME / DB_PASSWORD env overrides.
  • .github/workflows/dotnet.yml: added continue-on-error: true to the Slack "Report Status" step, so the Slack action (still ravsamhq/notify-slack-action@v1) can't fail the build. It did not bump any packages. The docs: clarify DB env overrides #146 description says it left the dependency refresh to this PR.

What's still only in #145. main today still pins the old versions:

  • API: Swashbuckle.AspNetCore 6.5.0 → 10.2.3, Swashbuckle.AspNetCore.Annotations 8.1.1 → 10.2.3, BCrypt.Net-Next 4.1.0 → 4.2.0, CouchbaseNetClient / Couchbase.Extensions.DependencyInjection 3.9.1 → 3.9.3
  • Program.cs: using Microsoft.OpenApi.Models; → using Microsoft.OpenApi;. Swashbuckle 10.x needs this.
  • Tests: Microsoft.NET.Test.Sdk 17.11.1 → 18.7.0, xunit.runner.visualstudio 2.8.2 → 3.1.5, coverlet.* 6.0.4 → 10.0.1, Microsoft.AspNetCore.Mvc.Testing 8.0.15 → 8.0.22
  • Workflow: notify-slack-action@v1 → @2.5.0

Current state. GitHub shows the PR as conflicting. The conflict is only in dotnet.yml: #146 added continue-on-error: true right above the uses: line that this PR bumps. To fix it, keep both changes (continue-on-error: true plus @2.5.0). The last green CI run on this branch was on 2026-07-06, and a few of these packages may have newer releases since then.

I can rebase onto main, resolve the conflict that way, check for newer versions, and re-run CI. Or if you'd rather rely on Dependabot, we can close this PR. Let me know which you prefer.

@ejscribner

Copy link
Copy Markdown
Contributor

@dex-the-ai Why don't you re-create this PR yourself. Check if other dependencies need updating too now that some time has passed. I want this PR created under your account so its easier to track. Once you've created a replacement PR that supersedes this one, close this PR.

@dex-the-ai

Copy link
Copy Markdown
Contributor

@ejscribner Done. The replacement is #147, opened from my account and rebuilt on current main. It keeps #146's continue-on-error: true on the Slack step and #146's README changes. I'm closing this PR now in favor of #147.

Updates found since this PR was opened. Compared with what's here, #147 also bumps:

  • CouchbaseNetClient and Couchbase.Extensions.DependencyInjection to 3.9.6 (3.9.3 here)
  • Microsoft.NET.Test.Sdk to 18.10.1 (18.7.0 here)
  • xunit.runner.visualstudio to 4.0.0 (3.1.5 here)
  • coverlet.collector and coverlet.msbuild to 10.1.0 (10.0.1 here)
  • Microsoft.AspNetCore.Mvc.Testing to 8.0.31 (8.0.22 here). This is still the latest 8.0.x, because 10.x needs net10.0.
  • GitHub Actions: actions/checkout v2 → v7 and actions/setup-dotnet v1 → v6. These weren't in this PR.

Unchanged from this PR: BCrypt.Net-Next 4.2.0, Swashbuckle.AspNetCore and Annotations 10.2.3 (with the Microsoft.OpenApi namespace change), and notify-slack-action 2.5.0.

Local results. With the .NET 8 SDK against Couchbase 7.6.4 and travel-sample: restore and build are clean, with 0 warnings. All 35/35 integration tests pass. Swagger JSON returns OpenAPI 3.0.4 with 7 paths, and the Swagger UI returns 200.

One thing to know about CI. While checking #147, I found that the workflow on main has never actually run the integration tests. It only builds the API project, so dotnet test --no-build has nothing to run. I fixed that in #147. Now that the tests really run, all 35 fail in CI because the CI Capella cluster's node hostnames don't resolve from the runner. Unchanged main code fails the same way, so the package updates aren't the cause. Details are in #147 (comment). Someone needs to check that the CI cluster is running and reachable.

@dex-the-ai

Copy link
Copy Markdown
Contributor

Superseded by #147.

@dex-the-ai dex-the-ai closed this Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants