Skip to content

chore(deps): Bump the build-tooling group with 2 updates - #12

Merged
milten89 merged 2 commits into
developfrom
dependabot/nuget/develop/build-tooling-b8555df121
Oct 1, 2026
Merged

milten89 merged 2 commits into
developfrom
dependabot/nuget/develop/build-tooling-b8555df121

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Updated Microsoft.SourceLink.GitHub from 10.0.301 to 10.0.401.

Release notes

Sourced from Microsoft.SourceLink.GitHub's releases.

10.0.401

Release

What's Changed

... (truncated)

10.0.400

You can build .NET 10.0 from the repository by cloning the release tag v10.0.400 and following the build instructions in the main README.md.

Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.

Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023

10.0.303

You can build .NET 10.0 from the repository by cloning the release tag v10.0.303 and following the build instructions in the main README.md.

Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.

Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023

10.0.302

You can build .NET 10.0 from the repository by cloning the release tag v10.0.302 and following the build instructions in the main README.md.

Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.

Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023

Commits viewable in compare view.

Updated Nerdbank.GitVersioning from 3.10.91 to 3.10.94.

Release notes

Sourced from Nerdbank.GitVersioning's releases.

3.10.94

What's Changed

Full Changelog: dotnet/Nerdbank.GitVersioning@v3.10.91...v3.10.94

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Microsoft.SourceLink.GitHub from 10.0.301 to 10.0.401
Bumps Nerdbank.GitVersioning from 3.10.91 to 3.10.94

---
updated-dependencies:
- dependency-name: Microsoft.SourceLink.GitHub
  dependency-version: 10.0.401
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: build-tooling
- dependency-name: Nerdbank.GitVersioning
  dependency-version: 3.10.94
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: build-tooling
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Dependency updates label Oct 1, 2026
@dependabot
dependabot Bot requested a review from milten89 as a code owner October 1, 2026 14:33
@dependabot dependabot Bot added the dependencies Dependency updates label Oct 1, 2026
@milten89

milten89 commented Oct 1, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase

@milten89
milten89 merged commit 60cf2a1 into develop Oct 1, 2026
8 checks passed
@milten89
milten89 deleted the dependabot/nuget/develop/build-tooling-b8555df121 branch October 1, 2026 19:18
milten89 added a commit that referenced this pull request Oct 1, 2026
- P1: drop item 11, which #22 fixed (the #23 merge put it back); add
  item 27, the unconfirmed gold publication hour.
- P2: items 12 and 13 describe what is left after #16-#18; item 26
  (WireMock error paths per client) goes with item 12.
- P3: item 20 is no longer a vulnerability after #12; item 21 notes
  what is documented; new items 24 (Microsoft.Testing.Platform, blocks
  Dependabot #11) and 25 (outdated GITHUB-SETUP.md). Item 22 points
  to the new prose skills.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
milten89 added a commit that referenced this pull request Oct 1, 2026
- P1: drop item 11, which #22 fixed (the #23 merge put it back); add
  item 27, the unconfirmed gold publication hour.
- P2: items 12 and 13 describe what is left after #16-#18; item 26
  (WireMock error paths per client) goes with item 12.
- P3: item 20 is no longer a vulnerability after #12; item 21 notes
  what is documented; new items 24 (Microsoft.Testing.Platform, blocks
  Dependabot #11) and 25 (outdated GITHUB-SETUP.md). Item 22 points
  to the new prose skills.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
milten89 added a commit that referenced this pull request Oct 2, 2026
* Simplify NBP client construction and stop mutating HttpClient

ADR-0007: `new NbpGoldPriceClient(httpClient)` works on its own.

- Each client has two constructors: (HttpClient) and (HttpClient,
  NbpOptions?, INbpUrlBuilderFactory?, TimeProvider?, logger?,
  traceSource?). The URL builder factory is no longer required.
- Remove ConfigureForNbpApi. It set BaseAddress/Timeout on a
  caller-owned HttpClient (which throws after the first request and
  prevents sharing one HttpClient), and was a second way to configure.
- Base URL: NbpOptions.ApiUrl, then HttpClient.BaseAddress, then
  NbpOptions.DefaultApiUrl; requests use absolute URIs. A missing
  BaseAddress no longer makes HttpClient throw.
- NbpOptions.Timeout is optional (default: the HttpClient's timeout);
  when set, it is applied per request. NbpOptions.DefaultTimeout and
  the 10 s default are gone.
- The request executor moves from HttpClientExtensions.GetNbpAsync to
  an internal NbpConnection (Common/), which PR #12's Http package will
  replace.
- NbpUrlBuilderFactory caches per instance instead of process-wide.
- README: usage section (one-line client, NbpOptions, base URL order).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Apply review fixes to NBP client construction

- Report the effective send-phase deadline: NbpOptions.Timeout can shorten
  HttpClient.Timeout but not extend it; document this.
- Reject timeouts above int.MaxValue ms and base URLs with a query or fragment.
- Ignore a leading '/' in request paths so the base path is kept.
- Document that options are read once; rename and move ctor tests.
- Backlog: DI must register with factory lambdas; private-field ctor tests
  and hand-written gold bodies recorded in items 30 and 26.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant