Skip to content

Bump the nuget-patch-and-minor group with 2 updates - #3130

Merged
erikdarlingdata merged 4 commits into
devfrom
dependabot/nuget/dev/nuget-patch-and-minor-ae8f6e9429
Sep 7, 2026
Merged

erikdarlingdata merged 4 commits into
devfrom
dependabot/nuget/dev/nuget-patch-and-minor-ae8f6e9429

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Updated AWSSDK.PI from 4.0.100.11 to 4.0.100.12.

Release notes

Sourced from AWSSDK.PI's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated AWSSDK.RDS from 4.0.104.4 to 4.0.105.1.

Release notes

Sourced from AWSSDK.RDS's releases.

No release notes found for this version range.

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps AWSSDK.PI from 4.0.100.11 to 4.0.100.12
Bumps AWSSDK.RDS from 4.0.104.4 to 4.0.105.1

---
updated-dependencies:
- dependency-name: AWSSDK.PI
  dependency-version: 4.0.100.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-and-minor
- dependency-name: AWSSDK.RDS
  dependency-version: 4.0.105.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-and-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Sep 7, 2026

Copy link
Copy Markdown
Owner

Review summary

Dependabot group bump of two AWS SDK packages in Directory.Packages.props:11-12:

  • AWSSDK.PI 4.0.100.11 → 4.0.100.12 (patch)
  • AWSSDK.RDS 4.0.104.4 → 4.0.105.1 (minor)

Both stay within the AWS SDK v4 line and cover the RDS/PI collectors that back the AWS observability path. No breaking APIs expected at this delta.

Checks

  • Base branch: dev — correct.
  • PlanAnalyzer sync: N/A — no Services/PlanAnalyzer.cs change on either side.
  • Schema/upgrades: N/A — no .sql touched.
  • Lite-first ordering: N/A — dependency bump only.
  • SignPath/build: N/A — .github/workflows/build.yml unchanged; signing profile stays test-signing.
  • Test coverage: N/A — no logic change.

Attention

Nothing blocking. Worth a quick sanity build + a run of Lite.Tests to confirm the RDS/PI collector shapes still bind — AWS SDK minor bumps have occasionally shuffled model classes even within a major.


Generated by Claude Code

Copy link
Copy Markdown
Owner

CI failure — Darling whole-tree guards

The dotnet restore --locked-mode on Darling/Darling.Tests/Darling.Tests.csproj fails because Dependabot bumped the AWSSDK versions in Directory.Packages.props but didn't regenerate the packages.lock.json files:

error NU1004: Mistmatch between the requestedVersion of a lock file dependency marked as
CentralTransitive and the version specified in the central package management file.
Lock file version [4.0.100.11, ), central package management version [4.0.100.12, ).

Root cause is this PR's diff (the AWSSDK.PI/AWSSDK.RDS bumps); it's not an infra flake or an unrelated failure.

Fix: regenerate the affected lock files with dotnet restore --force-evaluate (start with Darling/Darling.Tests — the log stopped at the first project, so other projects transitively referencing AWSSDK.PI/RDS may also need it) and commit the updated packages.lock.json files. Or, if you want the bot to redo it, ·@·d·ependabot r·ecreate to reroll the PR with fresh locks.

Per my review posture I'm not pushing anything — flagging for the maintainer.


Generated by Claude Code

@erikdarlingdata

Copy link
Copy Markdown
Owner

Claude posting for Erik Darling

This is red on NU1004 because Dependabot moves Directory.Packages.props and does not regenerate the packages.lock.json files that go with it. One command on this branch clears it:

dotnet restore PerformanceMonitor.sln --force-evaluate

then commit the lock files it rewrites. On a CRLF checkout that is Darling/Darling.Tests/packages.lock.json only — seven lines, AWSSDK.PI 4.0.100.11 -> .12 and the AWSSDK.Core 4.0.102.1 -> .3 it pulls with it. A restore run on Linux or macOS also rewrites the other eight lock files with LF; git normalises those away on add.

Worth knowing while this sits: Darling whole-tree guards is not a required check on dev, so this pull request reads UNSTABLE rather than BLOCKED — it is mergeable today, with lock files that do not match the props file it ships. #3147 makes the required build check able to report the mismatch, which it could not before.

Restore in locked mode fails NU1004 when Directory.Packages.props moves a
CentralTransitive version and the lock file still pins the previous range.
@claude

claude Bot commented Sep 7, 2026

Copy link
Copy Markdown

Reviewed. This is a routine dependabot dependency bump (AWSSDK.PI 4.0.100.11→4.0.100.12, AWSSDK.RDS 4.0.104.4→4.0.105.1) plus a lock-file regeneration commit to fix an NU1004 restore failure in Darling.Tests. No T-SQL/collector code is touched, so the style conventions don't apply. AWSSDK is Darling-only (used for RDS/PI cloud metrics) with no Lite counterpart, so there's no parity drift here. Version bumps in Directory.Packages.props and the lock file are consistent. No correctness, security, or performance concerns found.

@claude

claude Bot commented Sep 7, 2026

Copy link
Copy Markdown

Reviewed. This is a routine Dependabot patch bump (AWSSDK.PI 4.0.100.11→4.0.100.12, AWSSDK.RDS 4.0.104.4→4.0.105.1) plus the corresponding Darling/Darling.Tests/packages.lock.json regeneration (including the transitive AWSSDK.Core bump to 4.0.102.3). No T-SQL, application logic, or collector code is touched, so there's nothing to check against the style guide. No Lite/Darling parity concerns — this only affects Darling's test lockfile and the shared central package versions file, and Lite doesn't consume these AWS packages. No security or performance impact. LGTM.

@claude

claude Bot commented Sep 7, 2026

Copy link
Copy Markdown

Reviewed. This is a routine Dependabot patch bump (AWSSDK.PI 4.0.100.11→4.0.100.12, AWSSDK.RDS 4.0.104.4→4.0.105.1), touching only Directory.Packages.props and the Darling.Tests lockfile. No T-SQL, application code, or Lite/Darling parity surface is touched, so none of the review focus areas (correctness, parity drift, security, performance) apply here. No concerns — looks safe to merge.

@erikdarlingdata
erikdarlingdata merged commit feba2de into dev Sep 7, 2026
8 checks passed
@erikdarlingdata
erikdarlingdata deleted the dependabot/nuget/dev/nuget-patch-and-minor-ae8f6e9429 branch September 7, 2026 23:04
erikdarlingdata added a commit that referenced this pull request Sep 7, 2026
Directory.Packages.props conflicted because #3130 bumped the AWS SDK versions in the
same ItemGroup region. Resolved to the newer version of each package on both sides:
AWSSDK.PI 4.0.100.12, AWSSDK.RDS 4.0.105.1, BlackwellSystems.Gcf 1.0.0. The lock file
is generated, so it was resolved by regenerating it against the merged props rather
than by choosing a side.
erikdarlingdata added a commit that referenced this pull request Sep 9, 2026
…ix merged pull requests (#3213)

* Record the CHANGELOG entries for thirty-one changes across twenty-five merged pull requests

Applies the `[Unreleased]` entries for the pull requests merged to `dev` from #3150 (the
previous batch) through #3203. Lanes do not edit `CHANGELOG.md` -- every one of them appends
to the same block, so a per-PR edit conflicts with whichever sibling merges first -- and the
entry text rides each PR's own description instead. This is the periodic commit that applies
it.

`CHANGELOG.md` only, 56 insertions and no deletions: 31 entries prepended inside
`## [Unreleased]` (6 under `### Added`, 2 under `### Changed`, 23 under `### Fixed`), newest
merge first within each section, plus the 25 link-reference definitions they need appended at
the foot of the file. Nothing already in the block was edited, reworded or reordered.

Three of the 28 pull requests in the range earn no entry, each on measured precedent rather
than judgement: #3150 is the previous batch pass itself, and no batch pass -- #2260, #2980,
#3150 -- is cited anywhere in the file; #3130 and #3131 are routine Dependabot bumps, and
none of the six merged Dependabot pull requests in the repository's history is cited either.

Two pull requests carried no entry text anywhere, so theirs are written from their
descriptions: #3176 (`pg_index_bloat`'s measured block rate) and #3184 (the PostgreSQL
target's permissions section).

* Record #3205's entry, which arrived on the merged base mid-batch

#3205 merged while this batch was assembled, so `origin/dev` was merged in rather than rebased
and its entry lands on top. An entry omitted because it arrived mid-batch is how a backlog
restarts, and the batch's purpose is to make `[Unreleased]` current at its own merged base.

One entry under `### Changed`, newest merge first ahead of #3195's, plus its link-reference
definition. #3205 has no other pull request in the range behind it.

* Take #3164's and #3166's entries from the lane handoff files instead of the PR bodies

The entry text does not only ride the PR description. #3150's own account of the previous
batch says 11 of its 66 entries came from a lane's handoff file in
`~/Documents/pm-issue-queue-inbox/inbox/` rather than the body, and three files there carry
dedicated entry text inside this range: `3164-changelog-entry.md`, `3166-changelog-entry.md`
and `3169-changelog-entry.md`. Searching only the bodies missed the first two.

- **#3164** (PR #3176) is no longer written from the PR description. Its lane wrote a full
  entry, and that text is used verbatim: it carries the 1,036 blocks/s upper bound, the
  reason the decoupling #3153 deferred is unreachable, the declined command-deadline route,
  the census deliberately not restated at the new ceiling, and the mutation that caught
  nothing. `[#2997]` joins the definition block at its ascending position, which that text
  cites and the file did not define.
- **#3166** (PR #3168, absorbed and superseded by #3178) had no entry at all. #3178 grouped
  it into its own citation with a one-line summary, but its lane wrote a separate entry for
  the census that took `HeaviestHourlyRefreshObservedCeilingSeconds` from 594 s to 896 s and
  inverted the watch-line ordering. It sits beside #3178's, on #3178's merge.
- **#3191's entry** said "#3184 named four of the six". #3184 was squash-merged and the
  four-of-six state never reached `dev`; it was a commit inside that PR, corrected before
  merge. "shipped" in this file means merged, so the clause now says a commit in #3184, which
  is what the #3187 lane's own report establishes.

`CHANGELOG.md` only, 60 insertions and no deletions against `origin/dev`: 33 entries
(6 Added, 3 Changed, 24 Fixed) and 27 definitions. All 15 definition runs keep the ordering
they had, 9 of 15 ascending before and after.

* Use the staged #3184 entry text instead of one written from the PR description

#3184's entry now exists, staged by the lane that did the work, so the batch no longer
invents one. Used verbatim, in `### Fixed` where its author targeted it and for the reason
they gave: the section did not merely lack detail, it asserted "One role covers every
collector", which is false in the direction that fails silently and which an operator would
act on.

Their text carries what a description-derived entry could not: the `pg_read_all_data` grant
is PostgreSQL 14+ and the pre-14 fallback the section gave was `GRANT SELECT` on a schema,
which is not valid PostgreSQL at all; the six collectors that need an extension, four of
which additionally need `shared_preload_libraries` and a server restart; and why
`pg_index_bloat` is unaffected by any grant. Both figures are live pre-change store reads
rather than estimates.

The citation is `[#3184]`, the pull request, because the change has no issue behind it, and
its definition uses the `/pull/` form. `CHANGELOG.md` only, still 60 insertions and no
deletions against `origin/dev`.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant