Skip to content

chore(deps): bump Verify.XunitV3 to 32.0.0, add dependabot - #378

Merged
Tim81 merged 1 commit into
mainfrom
chore/verify-32-dependabot
Aug 31, 2026
Merged

chore(deps): bump Verify.XunitV3 to 32.0.0, add dependabot#378
Tim81 merged 1 commit into
mainfrom
chore/verify-32-dependabot

Conversation

@Tim81

@Tim81 Tim81 commented Aug 31, 2026

Copy link
Copy Markdown
Owner

Closes #221.

Verify.XunitV3 31.28.0 -> 32.0.0. 32.0.0's dependency on xunit.v3.extensibility.core is [3.2.2, ), an open lower bound already satisfied by the xunit.v3 3.2.2 pin in Directory.Packages.props, so this is independent of #200's xunit v4 migration.

Measured transitive delta against the base commit's restore: Verify itself moves 31.28.0 -> 32.0.0 (in lockstep with Verify.XunitV3), DiffEngine moves 19.3.3 -> 20.0.0 (a major), and Microsoft.Bcl.AsyncInterfaces moves 10.0.10 -> 10.0.11. Argon and SimpleInfoName were already in 31.28.0's closure and did not move.

DiffEngine 20.0.0's real behavior change, confirmed by inspecting the shipped assembly (BuildServerDetector/DisabledChecker/ContinuousTestingDetector are otherwise unchanged between the two versions): it now reads its disable flag lazily instead of capturing it once at type-init (VerifyTests/DiffEngine#825), and it installs a bundled viewer as an always-available last-resort tool. A detection miss that was a harmless no-op in 19.x could now launch a GUI.

  • ci.yml's Test step sets DiffEngine_Disabled: true explicitly against that.
  • tests/Directory.Build.props sets <DiffEngineBundledViewer>false</DiffEngineBundledViewer>. This drops the bundled viewer binary and the DiffEngine.ViewerDirectory stamp DiffEngine's build targets otherwise write into each test project's runtimeconfig.json (verified: rebuilding with the property set removes DiffEngine.ViewerDirectory from runtimeconfig.json while DiffEngine.TargetFramework remains) -- that stamp also carries a username-bearing absolute path, so this keeps it out of build artifacts. It does not stop a developer's own installed diff tool (VS, Rider, VS Code, WinMerge) from launching on a snapshot failure; only DiffEngine_Disabled does that.

Also adds .github/dependabot.yml (did not exist), covering nuget, github-actions, and dotnet-sdk, weekly:

  • nuget groups minor/patch bumps into one PR and excludes System.Security.Cryptography.Pkcs (the one shipped runtime dependency, whose patches change emitted CMS/PAdES bytes) from that group; majors stay individual so a snapshot-risk major like this one stays attributable to its own PR.
  • xunit.v3* (matching xunit.v3 and xunit.v3.assert) and xunit.runner.visualstudio majors are ignored, citing Migrate to Microsoft.Testing.Platform for xunit.v3 4.x #200's deliberate hold on the v3-to-v4 migration.
  • dotnet-sdk covers the global.json feature-band pin from ci: pin global.json and CI to the same SDK band #379. That updater does not consider rollForward, so it will propose SDKs outside the pinned 10.0.4xx band as readily as ones inside it -- intentionally: each such PR is the deliberate band-move signal ci: pin global.json and CI to the same SDK band #379's CONTRIBUTING rule calls for, not noise to dismiss.
  • github-actions carries no group: every action here is currently pinned to a floating major tag, so only major bumps ever surface.

Verification

  • dotnet build VellumPdf.slnx: 0 errors, 0 warnings.
  • dotnet test VellumPdf.slnx: all 7 test projects passed, 0 failures (Kernel, Reader, Layout, Barcodes, Cli, Conformance, TestSupport).
  • git status --porcelain after the full test run shows only the files in this diff -- no .verified.* file changed anywhere under tests/.
  • dotnet list VellumPdf.slnx package --vulnerable --include-transitive: no vulnerable packages.
  • dotnet format VellumPdf.slnx --verify-no-changes: passes.
  • pwsh ./eng/clean-room-check.ps1: passes.
  • .github/dependabot.yml validated against the official dependabot-2.0 JSON schema (schemastore.org) with jsonschema.validate -- no errors.

@Tim81 Tim81 added this to the v2.3 — Reader robustness milestone Aug 31, 2026
@Tim81
Tim81 force-pushed the chore/verify-32-dependabot branch from a82dd43 to fe92c04 Compare August 31, 2026 06:36
@Tim81 Tim81 changed the title Bump Verify.XunitV3 to 32.0.0 and add dependabot config chore(deps): bump Verify.XunitV3 to 32.0.0, add dependabot Aug 31, 2026
@Tim81
Tim81 force-pushed the chore/verify-32-dependabot branch 2 times, most recently from f05c56c to 6aae181 Compare August 31, 2026 07:55
The dependency floor on xunit.v3.extensibility.core is [3.2.2, ), an
open lower bound already satisfied by the xunit.v3 3.2.2 pin, so this
is independent of the xunit v4 migration tracked separately (#200).

The transitives that actually moved: Verify itself (31.28.0 to
32.0.0, in lockstep with Verify.XunitV3), DiffEngine (19.3.3 to
20.0.0, a major), and Microsoft.Bcl.AsyncInterfaces (10.0.10 to
10.0.11). Argon and SimpleInfoName were already in 31.28.0's closure.

DiffEngine 20.0.0 reads its disable flag lazily instead of capturing
it once at type-init (VerifyTests/DiffEngine#825) and now installs a
bundled viewer as an always-available last-resort tool, so a
detection miss that was a harmless no-op in 19.x could launch a GUI.
CI sets DiffEngine_Disabled explicitly against that, and the test
projects opt out of the bundled viewer, which also keeps a
username-bearing absolute path out of runtimeconfig.json. Neither
setting reaches a developer's own installed diff tool; only
DiffEngine_Disabled does that.

Adds .github/dependabot.yml, missing until now: nuget, github-actions,
and dotnet-sdk, weekly. Minor/patch bumps group per ecosystem; majors
stay individual so a snapshot-risk major like this one is
attributable to its own PR. The nuget group excludes the one shipped
runtime dependency, whose patches change emitted CMS/PAdES bytes,
from that batch, and ignores xunit.v3* and xunit.runner.visualstudio
majors pending #200's hold. dotnet-sdk does not consider rollForward,
so it will propose SDKs outside the pinned 10.0.4xx band by design:
each such PR is the deliberate band-move signal #379's CONTRIBUTING
rule calls for.
@Tim81
Tim81 force-pushed the chore/verify-32-dependabot branch from 6aae181 to 42ae342 Compare August 31, 2026 08:58
@Tim81
Tim81 merged commit 0be4bb8 into main Aug 31, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bump Verify.XunitV3 31.28.0 → 32.0.0 (independent of #200)

1 participant