Skip to content

Bump NuGet.Packaging and NuGet.Protocol - #201

Closed
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/nuget/microsoft-307f0608ad
Closed

Bump NuGet.Packaging and NuGet.Protocol#201
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/nuget/microsoft-307f0608ad

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 19, 2026

Copy link
Copy Markdown
Contributor

Updated NuGet.Packaging from 6.3.4 to 7.6.0.

Release notes

Sourced from NuGet.Packaging's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated NuGet.Protocol from 6.3.4 to 7.6.0.

Release notes

Sourced from NuGet.Protocol's releases.

No release notes found for this version range.

Commits viewable in compare view.

@dependabot dependabot Bot added the nuget NuGet packaging, publishing, or package metadata label Jul 19, 2026
@dependabot
dependabot Bot requested a review from cryptohivekeeper as a code owner July 19, 2026 11:27
@dependabot dependabot Bot added the nuget NuGet packaging, publishing, or package metadata label Jul 19, 2026
@CLAassistant

CLAassistant commented Jul 19, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you all sign our Contributor License Agreement before we can accept your contribution.
1 out of 2 committers have signed the CLA.

✅ cryptohivekeeper
❌ dependabot[bot]
You have signed the CLA already but the status is still pending? Let us recheck it.

@github-actions

github-actions Bot commented Jul 19, 2026

Copy link
Copy Markdown

⚠️ Deprecation Warning: The deny-licenses option is deprecated for possible removal in the next major release. For more information, see issue 997.

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 6 package(s) with unknown licenses.
See the Details below.

License Issues

tests/Threading.Analyzers/Threading.Analyzers.Tests.csproj

PackageVersionLicenseIssue Type
NuGet.Common7.6.0NullUnknown License
NuGet.Configuration7.6.0NullUnknown License
NuGet.Frameworks7.6.0NullUnknown License
NuGet.Packaging7.6.0NullUnknown License
NuGet.Protocol7.6.0NullUnknown License
NuGet.Versioning7.6.0NullUnknown License
Denied Licenses: GPL-3.0, AGPL-3.0, GPL-2.0, LGPL-2.0, LGPL-2.1, LGPL-3.0
Excluded from license check: pkg:nuget/NUnit.Console, pkg:nuget/OpenGost.Security.Cryptography

OpenSSF Scorecard

PackageVersionScoreDetails
nuget/NuGet.Common 7.6.0 UnknownUnknown
nuget/NuGet.Configuration 7.6.0 UnknownUnknown
nuget/NuGet.Frameworks 7.6.0 UnknownUnknown
nuget/NuGet.Packaging 7.6.0 UnknownUnknown
nuget/NuGet.Protocol 7.6.0 UnknownUnknown
nuget/NuGet.Versioning 7.6.0 UnknownUnknown
nuget/System.Security.Cryptography.Pkcs 8.0.1 🟢 6.5
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts⚠️ 0binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Pinned-Dependencies🟢 7dependency not pinned by hash detected -- score normalized to 7
Fuzzing🟢 10project is fuzzed
nuget/System.Security.Cryptography.ProtectedData 8.0.0 🟢 6.5
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts⚠️ 0binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Pinned-Dependencies🟢 7dependency not pinned by hash detected -- score normalized to 7
Fuzzing🟢 10project is fuzzed
nuget/System.Text.Encodings.Web 8.0.0 🟢 6.5
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts⚠️ 0binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Pinned-Dependencies🟢 7dependency not pinned by hash detected -- score normalized to 7
Fuzzing🟢 10project is fuzzed
nuget/System.Text.Json 8.0.5 🟢 6.5
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts⚠️ 0binaries present in source code
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Pinned-Dependencies🟢 7dependency not pinned by hash detected -- score normalized to 7
Fuzzing🟢 10project is fuzzed

Scanned Files

  • tests/Threading.Analyzers/Threading.Analyzers.Tests.csproj

@codecov

codecov Bot commented Jul 19, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@dependabot dependabot Bot changed the title Bump the microsoft group with 11 updates Bump NuGet.Packaging and NuGet.Protocol Jul 23, 2026
@dependabot
dependabot Bot force-pushed the dependabot/nuget/microsoft-307f0608ad branch from 1e4e811 to 0c92584 Compare July 23, 2026 22:23
Bumps NuGet.Packaging from 6.3.4 to 7.6.0
Bumps NuGet.Protocol from 6.3.4 to 7.6.0

---
updated-dependencies:
- dependency-name: Microsoft.Bcl.AsyncInterfaces
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: microsoft
- dependency-name: Microsoft.Bcl.Memory
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: microsoft
- dependency-name: Microsoft.Bcl.TimeProvider
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: microsoft
- dependency-name: Microsoft.CodeAnalysis.Analyzers
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: microsoft
- dependency-name: Microsoft.CodeAnalysis.CSharp
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: microsoft
- dependency-name: Microsoft.CodeAnalysis.CSharp.Workspaces
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: microsoft
- dependency-name: Microsoft.Extensions.ObjectPool
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: microsoft
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: microsoft
- dependency-name: Microsoft.VisualStudio.Threading
  dependency-version: 18.7.23
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: microsoft
- dependency-name: NuGet.Packaging
  dependency-version: 7.6.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: microsoft
- dependency-name: NuGet.Protocol
  dependency-version: 7.6.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: microsoft
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/nuget/microsoft-307f0608ad branch from 0c92584 to ff352e7 Compare July 24, 2026 05:50
@dependabot @github

dependabot Bot commented on behalf of github Jul 29, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/nuget/microsoft-307f0608ad branch July 29, 2026 03:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

nuget NuGet packaging, publishing, or package metadata

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants