Bump the nuget-minor-patch group with 21 updates - #425
Conversation
Bumps Google.Apis.AndroidPublisher.v3 from 1.75.0.4204 to 1.75.0.4215 Bumps Google.Apis.Calendar.v3 from 1.75.0.4200 to 1.75.0.4206 Bumps Hangfire.AspNetCore from 1.8.23 to 1.8.24 Bumps Hangfire.Core from 1.8.23 to 1.8.24 Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.9 to 10.0.10 Bumps Microsoft.AspNetCore.OpenApi from 10.0.9 to 10.0.10 Bumps Microsoft.EntityFrameworkCore from 10.0.9 to 10.0.10 Bumps Microsoft.EntityFrameworkCore.Design from 10.0.9 to 10.0.10 Bumps Microsoft.EntityFrameworkCore.InMemory from 10.0.9 to 10.0.10 Bumps Microsoft.EntityFrameworkCore.Sqlite from 10.0.9 to 10.0.10 Bumps Microsoft.Extensions.ApiDescription.Server from 10.0.9 to 10.0.10 Bumps Microsoft.Extensions.Caching.Abstractions from 10.0.9 to 10.0.10 Bumps Microsoft.Extensions.Caching.Memory from 10.0.9 to 10.0.10 Bumps Microsoft.Extensions.Caching.StackExchangeRedis from 10.0.9 to 10.0.10 Bumps Microsoft.Extensions.Http from 10.0.9 to 10.0.10 Bumps Microsoft.IdentityModel.JsonWebTokens from 8.19.1 to 8.19.2 Bumps Microsoft.NET.Test.Sdk from 18.8.0 to 18.8.1 Bumps Microsoft.OpenApi from 2.10.0 to 2.11.0 Bumps Scalar.AspNetCore from 2.16.11 to 2.16.16 Bumps Sentry.AspNetCore from 6.6.0 to 6.7.0 Bumps Stripe.net from 52.1.0 to 52.1.1 --- updated-dependencies: - dependency-name: Google.Apis.AndroidPublisher.v3 dependency-version: 1.75.0.4215 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Google.Apis.Calendar.v3 dependency-version: 1.75.0.4206 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Hangfire.AspNetCore dependency-version: 1.8.24 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Hangfire.Core dependency-version: 1.8.24 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Hangfire.Core dependency-version: 1.8.24 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.AspNetCore.OpenApi dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.EntityFrameworkCore dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.EntityFrameworkCore dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.EntityFrameworkCore.Design dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.EntityFrameworkCore.InMemory dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.Extensions.Caching.Memory dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.EntityFrameworkCore.InMemory dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.EntityFrameworkCore.Sqlite dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.Extensions.ApiDescription.Server dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.Extensions.Caching.Abstractions dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.Extensions.Caching.StackExchangeRedis dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.Extensions.Http dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.IdentityModel.JsonWebTokens dependency-version: 8.19.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.NET.Test.Sdk dependency-version: 18.8.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.NET.Test.Sdk dependency-version: 18.8.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.NET.Test.Sdk dependency-version: 18.8.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.NET.Test.Sdk dependency-version: 18.8.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Microsoft.OpenApi dependency-version: 2.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-minor-patch - dependency-name: Scalar.AspNetCore dependency-version: 2.16.16 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Sentry.AspNetCore dependency-version: 6.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-minor-patch - dependency-name: Stripe.net dependency-version: 52.1.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Stripe.net dependency-version: 52.1.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
There was a problem hiding this comment.
Code Review: PR #425 (thomasluizon/orbit-api)
Scope: PR #425 — "Bump the nuget-minor-patch group with 21 updates" (Dependabot)
Recommendation: APPROVE
Prior review check
No prior reviews with substantive content exist on this PR — the two existing reviews are empty-body APPROVED states from github-actions (automated dependency-check gate, not a prior /pr-review run), and there are zero review comments/threads. This is therefore a full review of the entire diff, not a delta.
What changed
The diff touches only 7 .csproj files — zero .cs source files, zero controllers, zero DTOs, zero tests added/removed:
src/Orbit.Api/Orbit.Api.csproj,src/Orbit.Application/Orbit.Application.csproj,src/Orbit.Infrastructure/Orbit.Infrastructure.csprojtests/Orbit.Analyzers.Tests/*.csproj,tests/Orbit.Application.Tests/*.csproj,tests/Orbit.Domain.Tests/*.csproj,tests/Orbit.Infrastructure.Tests/*.csproj
21 package version bumps, all patch/minor (Hangfire 1.8.23→24, EF Core family 10.0.9→10.0.10, JwtBearer 10.0.9→10.0.10, Sentry.AspNetCore 6.6.0→6.7.0, Stripe.net 52.1.0→52.1.1, Scalar.AspNetCore, Microsoft.OpenApi, Google.Apis.*, Microsoft.NET.Test.Sdk, etc.). Verified every bumped package lands on the same version everywhere it appears across the 7 files — no cross-project version skew that could cause an NU1605 downgrade warning or restore inconsistency.
Findings
Critical
None.
High
None.
Medium
None.
Low / Info
- [Info] New direct
PackageReferencewith zero code usage —src/Orbit.Application/Orbit.Application.csprojgainedMicrosoft.IdentityModel.JsonWebTokens(8.19.2) as an explicit direct reference; it previously wasn't listed there at all (onlyOrbit.Infrastructure.csprojhad it, backingInfrastructure/Services/JwtTokenService.cs). Confirmed via grep acrosssrc/Orbit.Applicationthat no.csfile references the package's types — this is a version pin to align the transitive dependency graph (likely pulled in via Stripe.net or another dependency), not new JWT-handling capability added to the CQRS layer.JwtTokenServiceremains correctly scoped toOrbit.Infrastructure. Not a security-boundary violation, not blocking.
Subagents
| Agent | Verdict |
|---|---|
| security-reviewer | PASS — independently verified no known CVEs in old or new versions of any bumped package; confirmed the Microsoft.IdentityModel.JsonWebTokens reference in Application is an inert transitive pin with no code usage and no auth-boundary shift. Corroborates the main review. |
| contract-aligner | N/A — gate not met (no DTO, Controller route, or packages/shared/endpoints.ts surface touched). |
Validation
| Check | Result |
|---|---|
| Build (dotnet) | N/A — Phase 6 explicitly skipped; CI's Build/Unit Tests/SonarCloud checks cover this |
| Tests (dotnet) | N/A — same |
Deferred — N/A dimensions
- No
apps/*files in this repo's diff — this is orbit-api only, no AI-slop/parity/i18n dimensions apply. - Cross-repo (
orbit-ui-mobile) dimensions not verifiable in this session — repo not checked out, and this PR touches no contract surface that would require a mobile-side check anyway. - No DTO/Controller/endpoint changed — contract-drift dimension N/A.
- Backend hard rules (timezone/authz/validation/logging/transactions) — gate technically fires since orbit-api is touched, but the diff carries no code implementing any of those concerns.
All 7 changed files were inspected directly (diff hunks read in full); no file was skipped.
What's good
- Coordinated, single-group Dependabot bump — all touched projects land on internally consistent versions, no partial/split upgrade left dangling.
- Purely mechanical: no source code, no behavior change, no new attack surface.
- No known CVEs closed or introduced; no stale hardcoded version strings left in
.github/workflows.
Recommendation
APPROVE. Clean, internally-consistent dependency-only bump with no Critical/High findings, corroborated by an independent security pass. The one Info-level observation (inert Microsoft.IdentityModel.JsonWebTokens reference in Orbit.Application.csproj) is not blocking.



Updated Google.Apis.AndroidPublisher.v3 from 1.75.0.4204 to 1.75.0.4215.
Release notes
Sourced from Google.Apis.AndroidPublisher.v3's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Google.Apis.Calendar.v3 from 1.75.0.4200 to 1.75.0.4206.
Release notes
Sourced from Google.Apis.Calendar.v3's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Hangfire.AspNetCore from 1.8.23 to 1.8.24.
Release notes
Sourced from Hangfire.AspNetCore's releases.
1.8.24
Release Notes
Hangfire.Core
Commits viewable in compare view.
Updated Hangfire.Core from 1.8.23 to 1.8.24.
Release notes
Sourced from Hangfire.Core's releases.
1.8.24
Release Notes
Hangfire.Core
Commits viewable in compare view.
Updated Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.AspNetCore.Authentication.JwtBearer's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.AspNetCore.OpenApi from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.AspNetCore.OpenApi's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.EntityFrameworkCore from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.EntityFrameworkCore's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.EntityFrameworkCore.Design from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.EntityFrameworkCore.Design's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.EntityFrameworkCore.InMemory from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.EntityFrameworkCore.InMemory's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.EntityFrameworkCore.Sqlite from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.EntityFrameworkCore.Sqlite's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.Extensions.ApiDescription.Server from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.Extensions.ApiDescription.Server's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.Extensions.Caching.Abstractions from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.Extensions.Caching.Abstractions's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.Extensions.Caching.Memory from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.Extensions.Caching.Memory's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.Extensions.Caching.StackExchangeRedis from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.Extensions.Caching.StackExchangeRedis's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.Extensions.Http from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.Extensions.Http's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.IdentityModel.JsonWebTokens from 8.19.1 to 8.19.2.
Release notes
Sourced from Microsoft.IdentityModel.JsonWebTokens's releases.
8.19.2
What's Changed
Full Changelog: AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@8.19.1...8.19.2
Commits viewable in compare view.
Updated Microsoft.NET.Test.Sdk from 18.8.0 to 18.8.1.
Release notes
Sourced from Microsoft.NET.Test.Sdk's releases.
18.8.1
What's Changed
Full Changelog: microsoft/vstest@v18.8.0...v18.8.1
Commits viewable in compare view.
Updated Microsoft.OpenApi from 2.10.0 to 2.11.0.
Release notes
Sourced from Microsoft.OpenApi's releases.
2.11.0
2.11.0 (2026-07-15)
Features
Bug Fixes
Commits viewable in compare view.
Updated Scalar.AspNetCore from 2.16.11 to 2.16.16.
Release notes
Sourced from Scalar.AspNetCore's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Sentry.AspNetCore from 6.6.0 to 6.7.0.
Release notes
Sourced from Sentry.AspNetCore's releases.
6.7.0
Features ✨
IgnoreTransactionsoption to filter out transactions by name, matching substrings or regular expressions against the transaction name (#5377) by @Adham-Kiwan in #5377SentryEventExtensions.IsFromUnhandledException) and terminal exceptions (SentryEventExtensions.IsFromTerminalException) by @jamescrosswell in #5177Fixes 🐛
Dependencies ⬆️
Deps
Other
Sentry.Extensions.LoggingFilters by @Flash0ver in #5297Commits viewable in compare view.
Updated Stripe.net from 52.1.0 to 52.1.1.
Release notes
Sourced from Stripe.net's releases.
52.1.1
See the changelog for more details.
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions