Skip to content

chore(deps): Bump the all-dependencies group with 48 updates (replaces #530)#531

Closed
JerrettDavis wants to merge 1 commit into
mainfrom
fix/grouped-deps-530
Closed

chore(deps): Bump the all-dependencies group with 48 updates (replaces #530)#531
JerrettDavis wants to merge 1 commit into
mainfrom
fix/grouped-deps-530

Conversation

@JerrettDavis
Copy link
Copy Markdown
Owner

Summary

This is a clean re-application of the grouped dependabot PR #530 on top of current main.

PR #530 (created by dependabot via grouped config) became conflicting because individual PRs #522-524, #526 were merged while #530 was in flight, causing CRLF-based three-way merge conflicts that GitHub could not auto-resolve.

Key changes

  • JD.SemanticKernel.Connectors.GitHubCopilot 0.1.46 → 0.1.55 (the package from original PR chore(deps): Bump JD.SemanticKernel.Connectors.GitHubCopilot from 0.1.46 to 0.1.55 #525)
  • JD.SemanticKernel.Extensions 0.1.71 → 0.1.90
  • JD.SemanticKernel.Extensions.Mcp 0.1.41 → 0.1.90
  • Microsoft.EntityFrameworkCore 9.0.6 → 10.0.8
  • MudBlazor 8.5.1 → 9.4.0
  • Microsoft.ML 4.0.0 → 5.0.0
  • YamlDotNet 17.0.0 → 18.0.0
  • NSec.Cryptography 25.4.0 → 26.4.0
  • SSH.NET 2024.2.0 → 2025.1.0
  • Plus ~39 other package updates (all . bumps to 10.0.8 or latest stable)
  • JD.AI.Plugins.SDK.csproj: added VersionOverride for Extensions packages
  • jetbrains.resharper.globaltools: 2025.3.3 → 2026.1.2

Closes

Supersedes dependabot PR #530 (conflicting).
Covers original task item PR #525 (GitHubCopilot 0.1.46 → 0.1.55).

🤖 Generated with Claude Code

Applies the grouped dependabot update (PR #530) cleanly on top of main.
Key changes:
- JD.SemanticKernel.Connectors.GitHubCopilot 0.1.46 -> 0.1.55
- JD.SemanticKernel.Extensions 0.1.71 -> 0.1.90
- JD.SemanticKernel.Extensions.Mcp 0.1.41 -> 0.1.90
- Microsoft.EntityFrameworkCore 9.0.6 -> 10.0.8
- MudBlazor 8.5.1 -> 9.4.0
- Microsoft.ML 4.0.0 -> 5.0.0
- YamlDotNet 17.0.0 -> 18.0.0
- NSec.Cryptography 25.4.0 -> 26.4.0
- SSH.NET 2024.2.0 -> 2025.1.0
- Plus 39 other package updates to current versions

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions
Copy link
Copy Markdown
Contributor

⚠️ Deprecation Warning: The deny-licenses option is deprecated for possible removal in the next major release. For more information, see issue 997.

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 2 package(s) with unknown licenses.
See the Details below.

License Issues

src/JD.AI.Plugins.SDK/JD.AI.Plugins.SDK.csproj

PackageVersionLicenseIssue Type
Microsoft.Extensions.DependencyInjection>= 0NullUnknown License
Microsoft.Extensions.Hosting.Abstractions>= 0NullUnknown License
Denied Licenses: GPL-2.0, GPL-3.0, AGPL-3.0

OpenSSF Scorecard

PackageVersionScoreDetails
nuget/Microsoft.Extensions.DependencyInjection >= 0 UnknownUnknown
nuget/Microsoft.Extensions.Hosting.Abstractions >= 0 UnknownUnknown

Scanned Files

  • src/JD.AI.Plugins.SDK/JD.AI.Plugins.SDK.csproj

@github-actions
Copy link
Copy Markdown
Contributor

Code Coverage


@github-actions
Copy link
Copy Markdown
Contributor

Test Results

0 tests   0 ✅  0s ⏱️
0 suites  0 💤
0 files    0 ❌

Results for commit c5f5d30.

@JerrettDavis
Copy link
Copy Markdown
Owner Author

Closing in favor of #532 which takes a minimal approach (only bumps GitHubCopilot 0.1.46→0.1.55) to avoid the MudBlazor v9 and ImageSharp v4 breaking changes included in this grouped update.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant