Skip to content

deps(nuget): Bump Microsoft.CodeAnalysis.CSharp from 4.11.0 to 5.6.0 - #138

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/Microsoft.CodeAnalysis.CSharp-5.6.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/Microsoft.CodeAnalysis.CSharp-5.6.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

Updated Microsoft.CodeAnalysis.CSharp from 4.11.0 to 5.6.0.

Release notes

Sourced from Microsoft.CodeAnalysis.CSharp's releases.

5.0.4

Release

5.0.2

Release Notes
Install Instructions

Repos

5.0.1

Release Notes
Install Instructions

Repo

Commits viewable in compare view.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot @github

dependabot Bot commented on behalf of github Jul 6, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, nuget. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from joslat as a code owner July 6, 2026 04:20
---
updated-dependencies:
- dependency-name: Microsoft.CodeAnalysis.CSharp
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/nuget/Microsoft.CodeAnalysis.CSharp-5.6.0 branch from 781b3f1 to 6d33439 Compare July 20, 2026 19:14
@github-actions

Copy link
Copy Markdown
Contributor

🔍 Cisco mcp-scanner result

=== MCP Scanner Results Summary ===

Scan Target: stdio:dotnet run --project src/maf-autopilot --framework net10.0 --no-build
Total tools scanned: 28
No results match the specified filters.

Scan covers prompt-injection, tool-poisoning, credential-harvesting,
code-execution, parameter-injection, cross-origin-escalation, and rug-pull
patterns. See docs/security.md for the canonical interpretation. This
check is a required gate — see the "Run mcp-scanner" step above for the
exact pass/fail evaluation.

@joslat

joslat commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Closing: the Roslyn analyzer package must keep a low Microsoft.CodeAnalysis floor so it loads in older SDKs/VS. Moving the analyzer to 5.6 would silently stop it loading for those users. The plan (ROADMAP R-03) is to move the tool's scanner to Roslyn 5.x while pinning the analyzer to 4.x via VersionOverride; a Dependabot ignore rule for Roslyn majors follows.

@joslat joslat closed this Oct 1, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/nuget/Microsoft.CodeAnalysis.CSharp-5.6.0 branch October 1, 2026 13:10
joslat added a commit that referenced this pull request Oct 1, 2026
…queue jams

- Microsoft.SourceLink.GitHub 10.0.300 -> 10.0.303 pulls the patched
  Microsoft.Build.Tasks.Git 10.0.303 (CVE-2026-62900 / GHSA-23fw-v26w-5fgq,
  medium, information disclosure; build-time only). Lock files refreshed.
- Dependabot: weekly grouped PRs per ecosystem (NuGet minor/patch, all
  Actions, all Docker base images) so five stale PRs can no longer fill the
  open-PR limit and block security/SDK bumps (the 2026-07 -> 10 jam).
- Ignore Microsoft.CodeAnalysis* majors: the analyzer must keep a low
  Roslyn floor (ROADMAP R-03); #137/#138 closed with that rationale.

The 7 green Actions/Docker PRs (#132-#136, #168, #169) were merged; #144,
#150, #151 were asked to recreate on top of the repaired CI.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant