Update aligned backend dependency packages - #1545
Merged
Merged
Conversation
Signed-off-by: Chris0Jeky <jeky.tck@gmail.com>
Owner
Author
|
Independent exact-head review — clean
Residual risk is limited to live OIDC-provider and live Sentry-vendor roundtrips; neither integration surface changed, and Sentry remains default-off. Hosted exact-head CI, thread/comment triage, and the post-push eligibility floor still gate merge. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Microsoft.IdentityModel.TokensandSystem.IdentityModel.Tokens.Jwtpackages from 8.19.2 to 8.21.0Sentry.AspNetCorefrom 6.7.0 to 6.8.0FsCheckandFsCheck.Xunitfrom 3.3.3 to 3.3.4main, because the old shared merge commit lacked the repository's literal DCO trailer even though the advisory hosted check passedThe replacement head contains one signed commit and does not rewrite the Dependabot branch.
Verification
dotnet build backend/Taskdeck.sln -c Release -m:1— passed, 0 errors (11 existing warnings)dotnet test backend/Taskdeck.sln -c Release -m:1 --no-build— 7,551 passed / 5 intentionally skipped / 0 faileddotnet list backend/Taskdeck.sln package --vulnerable --include-transitive— no vulnerable packages reportednode scripts/check-docs-governance.mjsnode scripts/check-golden-principles.mjsnode scripts/check-github-ops-governance.mjsgit diff --check origin/main...HEADThe full local run was performed on tree
29a611182f812579b254b8734b704a8d7bcd31d3. This PR's signed head has that exact tree.Documentation
docs/STATUS.md— no shipped behavior changeddocs/IMPLEMENTATION_MASTERPLAN.md— no roadmap or priority changeddocs/TESTING_GUIDE.md/docs/MANUAL_TEST_CHECKLIST.md— no verification flow changedTracking
Review / Priority V(no linked issue, so the documented fallback applies)CI Workflow Validation
Risk Notes