Skip to content

Commit 7fad757

Browse files
[Infra] Update dependency version syntax for renovate (#6505)
1 parent 2b40bd0 commit 7fad757

File tree

2 files changed

+13
-23
lines changed

2 files changed

+13
-23
lines changed

Directory.Packages.props

Lines changed: 12 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -3,17 +3,6 @@
33
<PropertyGroup>
44
<ManagePackageVersionsCentrally>true</ManagePackageVersionsCentrally>
55
<OTelLatestStableVer>1.12.0</OTelLatestStableVer>
6-
7-
<!--
8-
This is typically the latest annual release of .NET. Use this wherever
9-
possible and only deviate (use a specific version) when a package has a
10-
more specific patch which must be reference directly.
11-
-->
12-
<LatestRuntimeOutOfBandVer>9.0.0</LatestRuntimeOutOfBandVer>
13-
14-
<!-- Mitigate https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43485. -->
15-
<SystemTextEncodingsWebOutOfBandMinimumCoreAppVer>8.0.0</SystemTextEncodingsWebOutOfBandMinimumCoreAppVer>
16-
<SystemTextJsonOutOfBandMinimumCoreAppVer>8.0.5</SystemTextJsonOutOfBandMinimumCoreAppVer>
176
</PropertyGroup>
187

198
<!--
@@ -31,10 +20,10 @@
3120
3) Since version 3.1.0, the .NET runtime team is holding a high bar for backward compatibility on
3221
these packages even during major version bumps, so compatibility is not a concern here.
3322
-->
34-
<PackageVersion Include="Microsoft.Extensions.DependencyInjection.Abstractions" Version="$(LatestRuntimeOutOfBandVer)" />
35-
<PackageVersion Include="Microsoft.Extensions.Diagnostics.Abstractions" Version="$(LatestRuntimeOutOfBandVer)" />
36-
<PackageVersion Include="Microsoft.Extensions.Hosting.Abstractions" Version="$(LatestRuntimeOutOfBandVer)" />
37-
<PackageVersion Include="Microsoft.Extensions.Logging.Configuration" Version="$(LatestRuntimeOutOfBandVer)" />
23+
<PackageVersion Include="Microsoft.Extensions.DependencyInjection.Abstractions" Version="[9.0.0,)" />
24+
<PackageVersion Include="Microsoft.Extensions.Diagnostics.Abstractions" Version="[9.0.0,)" />
25+
<PackageVersion Include="Microsoft.Extensions.Hosting.Abstractions" Version="[9.0.0,)" />
26+
<PackageVersion Include="Microsoft.Extensions.Logging.Configuration" Version="[9.0.0,)" />
3827

3928
<!--
4029
OTel packages always point to latest stable release.
@@ -56,7 +45,7 @@
5645
3) The .NET runtime team provides extra backward compatibility guarantee to System.Diagnostics.DiagnosticSource
5746
even during major version bumps, so compatibility is not a concern here.
5847
-->
59-
<PackageVersion Include="System.Diagnostics.DiagnosticSource" Version="$(LatestRuntimeOutOfBandVer)" />
48+
<PackageVersion Include="System.Diagnostics.DiagnosticSource" Version="[9.0.0,)" />
6049
</ItemGroup>
6150

6251
<ItemGroup>
@@ -73,9 +62,10 @@
7362
<PackageVersion Include="System.Text.Encodings.Web" Version="4.7.2" />
7463
<PackageVersion Include="System.Text.Json" Version="4.7.2" />
7564

65+
<!-- Mitigate https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43485. -->
7666
<!-- Newer NETCoreApp runtimes need to be redirected to safe versions. -->
77-
<PackageVersion Update="System.Text.Encodings.Web" Version="$(SystemTextEncodingsWebOutOfBandMinimumCoreAppVer)" Condition="'$(TargetFrameworkIdentifier)' == '.NETCoreApp'" />
78-
<PackageVersion Update="System.Text.Json" Version="$(SystemTextJsonOutOfBandMinimumCoreAppVer)" Condition="'$(TargetFrameworkIdentifier)' == '.NETCoreApp'" />
67+
<PackageVersion Update="System.Text.Encodings.Web" Version="[8.0.0,)" Condition="'$(TargetFrameworkIdentifier)' == '.NETCoreApp'" />
68+
<PackageVersion Update="System.Text.Json" Version="[8.0.5,)" Condition="'$(TargetFrameworkIdentifier)' == '.NETCoreApp'" />
7969
</ItemGroup>
8070

8171
<!--
@@ -96,10 +86,10 @@
9686
<PackageVersion Include="Microsoft.CSharp" Version="4.7.0" />
9787
<PackageVersion Include="Microsoft.CodeAnalysis.PublicApiAnalyzers" Version="4.14.0" />
9888
<PackageVersion Include="Microsoft.Coyote" Version="1.7.11" />
99-
<PackageVersion Include="Microsoft.Extensions.DependencyInjection" Version="$(LatestRuntimeOutOfBandVer)" />
100-
<PackageVersion Include="Microsoft.Extensions.Hosting" Version="$(LatestRuntimeOutOfBandVer)" />
101-
<PackageVersion Include="Microsoft.Extensions.Http" Version="$(LatestRuntimeOutOfBandVer)" />
102-
<PackageVersion Include="Microsoft.Extensions.Logging.Abstractions" Version="$(LatestRuntimeOutOfBandVer)" />
89+
<PackageVersion Include="Microsoft.Extensions.DependencyInjection" Version="9.0.0" />
90+
<PackageVersion Include="Microsoft.Extensions.Hosting" Version="9.0.0" />
91+
<PackageVersion Include="Microsoft.Extensions.Http" Version="9.0.0" />
92+
<PackageVersion Include="Microsoft.Extensions.Logging.Abstractions" Version="9.0.0" />
10393
<PackageVersion Include="Microsoft.Extensions.Telemetry.Abstractions" Version="9.0.0" />
10494
<PackageVersion Include="Microsoft.NETFramework.ReferenceAssemblies" Version="1.0.3" />
10595
<PackageVersion Include="Microsoft.NET.Test.Sdk" Version="17.13.0" />

test/Directory.Build.targets

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99
reference is needed to mitigate:
1010
https://github.com/advisories/GHSA-hh2w-p6rv-4g7w. Remove this if Coyote
1111
publishes a fixed version. -->
12-
<PackageReference Include="System.Text.Json" VersionOverride="$(SystemTextJsonOutOfBandMinimumCoreAppVer)" />
12+
<PackageReference Include="System.Text.Json" VersionOverride="8.0.5" />
1313
</ItemGroup>
1414

1515
</Project>

0 commit comments

Comments
 (0)