From 1124177cabbb9e99031a311f8b439e21073c9e3b Mon Sep 17 00:00:00 2001 From: Stuart Meeks Date: Mon, 21 Sep 2026 06:21:47 +0000 Subject: [PATCH] chore(deps): bump SourceLink, xunit.v3, and CodeCoverage (safe subset of #89) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Applies only the non-floored, non-runtime dependency bumps from the Dependabot group in #89: - Microsoft.SourceLink.GitHub 10.0.400 -> 10.0.401 (build tooling, PrivateAssets=All) - xunit.v3 4.0.0 -> 4.0.1 (test-only) - Microsoft.Testing.Extensions.CodeCoverage 18.11.0 -> 18.11.2 (test-only) Deliberately EXCLUDES the three per-TFM-floored packages (Microsoft.Extensions.DependencyInjection.Abstractions, Microsoft.Extensions.Http, System.Security.Cryptography.ProtectedData). #89 rewrote their net8.0 floors from 8.0.x to 10.0.12, which violates the deliberate per-TFM floor policy (net8 LTS consumers must stay on their 8.0.x servicing line). Those floors are bumped by hand, per TFM, in their own reviewed commit — never as a side effect of an automated group bump. The Dependabot `ignore` gap that let #89 rewrite the net8 floor (a name-scoped, major-only ignore cannot protect a per-TFM floor when the same package name also appears in the net10 block) is cross-referenced to STANDARD.md 4.10 and is fixed upstream in NextIteration.Standards, then synced here. Supersedes #89. Co-Authored-By: Claude Opus 4.8 --- Directory.Packages.props | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/Directory.Packages.props b/Directory.Packages.props index 06dd7ab..786f65e 100644 --- a/Directory.Packages.props +++ b/Directory.Packages.props @@ -56,7 +56,7 @@ - + - - + +