Skip to content

[BLOCKED] build(deps): bump Microsoft.NETFramework.ReferenceAssemblies and packageurl-dotnet#1055

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/multi-4df1fbadcf
Closed

[BLOCKED] build(deps): bump Microsoft.NETFramework.ReferenceAssemblies and packageurl-dotnet#1055
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/multi-4df1fbadcf

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 17, 2025

Bumps Microsoft.NETFramework.ReferenceAssemblies and packageurl-dotnet. These dependencies needed to be updated together.
Updates Microsoft.NETFramework.ReferenceAssemblies from 1.0.3 to 1.0.3

Commits

Updates packageurl-dotnet from 1.1.0 to 1.3.0

Release notes

Sourced from packageurl-dotnet's releases.

1.3.0

What's Changed

New Contributors

Full Changelog: package-url/packageurl-dotnet@1.2.1...1.3.0

1.2.1

What's Changed

New Contributors

Full Changelog: package-url/packageurl-dotnet@1.2.0...1.2.1

1.2.0

What's Changed

New Contributors

Full Changelog: package-url/packageurl-dotnet@1.1.1...1.2.0

1.1.1

What's Changed

New Contributors

Full Changelog: package-url/packageurl-dotnet@1.1.0...1.1.1

Commits
  • a42c0b8 Encoded purl components as per the PURL specification. (#23)
  • ef9a9f0 Fix issues handling golang packages with multi-part namespaces. (#20)
  • 7b27f39 Standardize namespace and name normalization to match Python library (#22)
  • 810a771 Prevent lowercasing npm names to support grandfathered packages (#19)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…ageurl-dotnet

Bumps [Microsoft.NETFramework.ReferenceAssemblies](https://github.com/Microsoft/dotnet) and [packageurl-dotnet](https://github.com/package-url/packageurl-dotnet). These dependencies needed to be updated together.

Updates `Microsoft.NETFramework.ReferenceAssemblies` from 1.0.3 to 1.0.3
- [Commits](https://github.com/Microsoft/dotnet/commits)

Updates `packageurl-dotnet` from 1.1.0 to 1.3.0
- [Release notes](https://github.com/package-url/packageurl-dotnet/releases)
- [Commits](package-url/packageurl-dotnet@1.1.0...1.3.0)

---
updated-dependencies:
- dependency-name: Microsoft.NETFramework.ReferenceAssemblies
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: packageurl-dotnet
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .net code dependencies Pull requests that update a dependency file labels May 17, 2025
@dependabot dependabot Bot requested a review from a team as a code owner May 17, 2025 03:46
@dependabot dependabot Bot added .NET Pull requests that update .net code dependencies Pull requests that update a dependency file labels May 17, 2025
@DaveTryon
Copy link
Copy Markdown
Contributor

/azp run

@DaveTryon
Copy link
Copy Markdown
Contributor

This is a newer version of #327, which was intentionally blocked with this comment:

This is blocked upstream microsoft/component-detection#152.

We should probably wait until Component Detection updates, and update in lockstep.

@DaveTryon DaveTryon changed the title build(deps): bump Microsoft.NETFramework.ReferenceAssemblies and packageurl-dotnet [BLOCKED] build(deps): bump Microsoft.NETFramework.ReferenceAssemblies and packageurl-dotnet May 19, 2025
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 21, 2025

Looks like these dependencies are up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this May 21, 2025
@dependabot dependabot Bot deleted the dependabot/nuget/multi-4df1fbadcf branch May 21, 2025 16:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .net code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant