Skip to content

Refresh dependency pins and lock graphs - #116

Merged
jeremydixon22 merged 2 commits into
mainfrom
maintenance/dependabot-refresh-2026-08-24
Aug 24, 2026
Merged

Refresh dependency pins and lock graphs#116
jeremydixon22 merged 2 commits into
mainfrom
maintenance/dependabot-refresh-2026-08-24

Conversation

@jeremydixon22

@jeremydixon22 jeremydixon22 commented Aug 24, 2026

Copy link
Copy Markdown
Member

Summary

  • Refresh the Buildx action pin and the release-policy assertions that protect it.
  • Apply the pending AWS, Google, Azure Durable Functions, and Semantic Kernel package updates.
  • Regenerate every affected downstream NuGet lock graph so locked restores remain complete for all target frameworks.

This consolidates and supersedes #110-#115. PR #113 duplicates the Google.Apis.Core portion of #112.

PR #108 is intentionally excluded: the current CodeQL bundle (2.26.3) is built with Go 1.26 and emits extraction errors against Go 1.27. Upstream says Go 1.27 support will arrive in the next CodeQL release: github/codeql#22394 (comment). Retaining Go 1.26.6 preserves complete security analysis until that lands.

Verification

  • Relevant unit and conformance tests pass.
  • Public API, contract, and maturity documentation is updated when applicable.
  • Provider-specific behavior has an opt-in live gate and does not widen a portable claim.
  • No credentials, customer data, local paths, generated artifacts, or deployment identities are included.
  • Release artifacts and public export were rehearsed when a package, client, container, or workflow changed.

Local verification included locked restore, Release build, the deterministic .NET suite, Go tests, NuGet vulnerability audit, policy verifiers, and public-export rehearsal.

Public information review

Does this change expose new public information? No

Compatibility and operations

No application contract or deployment behavior changes. NuGet consumers receive patch/minor dependency refreshes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant