chore(deps): bump Verify.XunitV3 to 32.0.0, add dependabot - #378
Merged
Conversation
6 tasks
Tim81
force-pushed
the
chore/verify-32-dependabot
branch
from
August 31, 2026 06:36
a82dd43 to
fe92c04
Compare
Tim81
force-pushed
the
chore/verify-32-dependabot
branch
2 times, most recently
from
August 31, 2026 07:55
f05c56c to
6aae181
Compare
The dependency floor on xunit.v3.extensibility.core is [3.2.2, ), an open lower bound already satisfied by the xunit.v3 3.2.2 pin, so this is independent of the xunit v4 migration tracked separately (#200). The transitives that actually moved: Verify itself (31.28.0 to 32.0.0, in lockstep with Verify.XunitV3), DiffEngine (19.3.3 to 20.0.0, a major), and Microsoft.Bcl.AsyncInterfaces (10.0.10 to 10.0.11). Argon and SimpleInfoName were already in 31.28.0's closure. DiffEngine 20.0.0 reads its disable flag lazily instead of capturing it once at type-init (VerifyTests/DiffEngine#825) and now installs a bundled viewer as an always-available last-resort tool, so a detection miss that was a harmless no-op in 19.x could launch a GUI. CI sets DiffEngine_Disabled explicitly against that, and the test projects opt out of the bundled viewer, which also keeps a username-bearing absolute path out of runtimeconfig.json. Neither setting reaches a developer's own installed diff tool; only DiffEngine_Disabled does that. Adds .github/dependabot.yml, missing until now: nuget, github-actions, and dotnet-sdk, weekly. Minor/patch bumps group per ecosystem; majors stay individual so a snapshot-risk major like this one is attributable to its own PR. The nuget group excludes the one shipped runtime dependency, whose patches change emitted CMS/PAdES bytes, from that batch, and ignores xunit.v3* and xunit.runner.visualstudio majors pending #200's hold. dotnet-sdk does not consider rollForward, so it will propose SDKs outside the pinned 10.0.4xx band by design: each such PR is the deliberate band-move signal #379's CONTRIBUTING rule calls for.
Tim81
force-pushed
the
chore/verify-32-dependabot
branch
from
August 31, 2026 08:58
6aae181 to
42ae342
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #221.
Verify.XunitV3 31.28.0 -> 32.0.0. 32.0.0's dependency on xunit.v3.extensibility.core is [3.2.2, ), an open lower bound already satisfied by the xunit.v3 3.2.2 pin in Directory.Packages.props, so this is independent of #200's xunit v4 migration.
Measured transitive delta against the base commit's restore: Verify itself moves 31.28.0 -> 32.0.0 (in lockstep with Verify.XunitV3), DiffEngine moves 19.3.3 -> 20.0.0 (a major), and Microsoft.Bcl.AsyncInterfaces moves 10.0.10 -> 10.0.11. Argon and SimpleInfoName were already in 31.28.0's closure and did not move.
DiffEngine 20.0.0's real behavior change, confirmed by inspecting the shipped assembly (BuildServerDetector/DisabledChecker/ContinuousTestingDetector are otherwise unchanged between the two versions): it now reads its disable flag lazily instead of capturing it once at type-init (VerifyTests/DiffEngine#825), and it installs a bundled viewer as an always-available last-resort tool. A detection miss that was a harmless no-op in 19.x could now launch a GUI.
DiffEngine_Disabled: trueexplicitly against that.<DiffEngineBundledViewer>false</DiffEngineBundledViewer>. This drops the bundled viewer binary and theDiffEngine.ViewerDirectorystamp DiffEngine's build targets otherwise write into each test project's runtimeconfig.json (verified: rebuilding with the property set removesDiffEngine.ViewerDirectoryfrom runtimeconfig.json whileDiffEngine.TargetFrameworkremains) -- that stamp also carries a username-bearing absolute path, so this keeps it out of build artifacts. It does not stop a developer's own installed diff tool (VS, Rider, VS Code, WinMerge) from launching on a snapshot failure; onlyDiffEngine_Disableddoes that.Also adds .github/dependabot.yml (did not exist), covering nuget, github-actions, and dotnet-sdk, weekly:
nugetgroups minor/patch bumps into one PR and excludes System.Security.Cryptography.Pkcs (the one shipped runtime dependency, whose patches change emitted CMS/PAdES bytes) from that group; majors stay individual so a snapshot-risk major like this one stays attributable to its own PR.xunit.v3*(matching xunit.v3 and xunit.v3.assert) and xunit.runner.visualstudio majors are ignored, citing Migrate to Microsoft.Testing.Platform for xunit.v3 4.x #200's deliberate hold on the v3-to-v4 migration.dotnet-sdkcovers the global.json feature-band pin from ci: pin global.json and CI to the same SDK band #379. That updater does not consider rollForward, so it will propose SDKs outside the pinned 10.0.4xx band as readily as ones inside it -- intentionally: each such PR is the deliberate band-move signal ci: pin global.json and CI to the same SDK band #379's CONTRIBUTING rule calls for, not noise to dismiss.github-actionscarries no group: every action here is currently pinned to a floating major tag, so only major bumps ever surface.Verification
dotnet build VellumPdf.slnx: 0 errors, 0 warnings.dotnet test VellumPdf.slnx: all 7 test projects passed, 0 failures (Kernel, Reader, Layout, Barcodes, Cli, Conformance, TestSupport).git status --porcelainafter the full test run shows only the files in this diff -- no.verified.*file changed anywhere undertests/.dotnet list VellumPdf.slnx package --vulnerable --include-transitive: no vulnerable packages.dotnet format VellumPdf.slnx --verify-no-changes: passes.pwsh ./eng/clean-room-check.ps1: passes..github/dependabot.ymlvalidated against the official dependabot-2.0 JSON schema (schemastore.org) withjsonschema.validate-- no errors.