microsoft / microsoft/component-detection

Dependency Dashboard

Open
#139 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

dependencies
Dominant language
C#
Stars
553
Forks
135
Avg merge
20h 58m
Merged PRs (30d)
6

Description

This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
View this repository on the Mend.io Web Portal.

Rate-Limited

The following updates are currently rate-limited. To force their creation now, click on a checkbox below.

  • Update actions/setup-python digest to ece7cb0
  • Update dependency MSBuild.StructuredLogger to 2.3.246
  • Update dependency packageurl-dotnet to 2.0.1
  • Update dotnet monorepo (System.Formats.Asn1, System.Text.Json, dotnet-sdk, mcr.microsoft.com/dotnet/runtime-deps, mcr.microsoft.com/dotnet/sdk)
  • Update ossf/scorecard-action action to v2.4.4
  • Update shogo82148/actions-upload-release-asset action to v1.10.4
  • Update actions/setup-dotnet action to v5.4.0
  • Update dependency AwesomeAssertions to 9.6.0
  • Update dependency Moq to 4.20.72
  • Update dependency Polly to 8.8.0
  • Update dependency Serilog to 4.4.0
  • Update dependency Spectre.Console.Cli to 0.55.0
  • Update dependency Spectre.Console.Cli.Extensions.DependencyInjection to 0.29.0
  • Update github/codeql-action action to v4.38.1
  • Update mshick/add-pr-comment action to v3.12.0
  • Update mstest monorepo to 4.4.1 (MSTest.Analyzers, MSTest.Sdk, MSTest.TestFramework)
  • Update nuget monorepo to 7.9.0 (NuGet.ProjectModel, NuGet.Versioning)
  • Update release-drafter/release-drafter action to v7.7.0
  • Update spectre-console monorepo to 0.57.2 (Spectre.Console, Spectre.Console.Testing)
  • Update stefanzweifel/git-auto-commit-action action to v7.2.0
  • Update step-security/harden-runner action to v2.21.1
  • Update zizmorcore/zizmor-action action to v0.6.4
  • Update actions/checkout action to v7
  • Update actions/github-script action to v9
  • Update actions/setup-dotnet action to v6
  • Update actions/setup-python action to v7
  • Update codecov/codecov-action action to v7
  • Update dependency Microsoft.VisualStudio.Threading.Analyzers to v18
  • Update dependency MinVer to v8
  • Update dependency System.Reactive to v7
  • Update dependency Tomlyn.Signed to v2
  • Update dependency Valleysoft.DockerfileModel to v2
  • Update dependency yamldotnet to v18
  • Update dotnet monorepo to v10 (Microsoft.Extensions.Caching.Memory, Microsoft.Extensions.DependencyInjection, Microsoft.Extensions.DependencyInjection.Abstractions, Microsoft.Extensions.FileSystemGlobbing, Microsoft.Extensions.Http, Microsoft.Extensions.Logging, Microsoft.SourceLink.GitHub, System.Formats.Asn1, System.Text.Json, System.Threading.Tasks.Dataflow, dotnet-sdk)
  • Update mcr.microsoft.com/vscode/devcontainers/dotnet Docker tag to v10
  • Lock file maintenance
  • πŸ” Create all rate-limited PRs at once πŸ”

PR Edited (Blocked)

The following updates have been manually edited so Renovate will no longer make changes. To discard all commits and start over, click on a checkbox below.

Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

Detected Dependencies

devcontainer (1)
.devcontainer/devcontainer.json (1)
  • mcr.microsoft.com/vscode/devcontainers/dotnet 8.0 β†’ [Updates: 10.0]
dockerfile (1)
Dockerfile (2)
  • mcr.microsoft.com/dotnet/sdk 8.0-cbl-mariner2.0@sha256:a26c5bf4c47186df2fd290b74a2512d9830796d98b644fb12857b57a5244507d β†’ [Updates: 8.0-cbl-mariner2.0]
  • mcr.microsoft.com/dotnet/runtime-deps 8.0-cbl-mariner2.0@sha256:addba165ed9637fc02c63e9f66913deb7125dac90b5ca7d3f89d6d084c23f09b β†’ [Updates: 8.0-cbl-mariner2.0]
github-actions (11)
.github/workflows/build.yml (4)
  • step-security/harden-runner v2.16.0@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 β†’ [Updates: v2.21.1]
  • actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83dd β†’ [Updates: v6.1.0, v7.0.1]
  • actions/setup-dotnet v5.2.0@c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7 β†’ [Updates: v5.4.0, v6.0.0]
  • codecov/codecov-action v5.5.2@671740ac38dd9b0130fbe1cec585b89eea48d3de β†’ [Updates: v5.5.5, v7.1.1]
.github/workflows/codeql-analysis.yml (5)
  • step-security/harden-runner v2.16.0@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 β†’ [Updates: v2.21.1]
  • actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83dd β†’ [Updates: v6.1.0, v7.0.1]
  • github/codeql-action v4.33.0@b1bff81932f5cdfc8695c7752dcee935dcd061c8 β†’ [Updates: v4.38.1]
  • github/codeql-action v4.33.0@b1bff81932f5cdfc8695c7752dcee935dcd061c8 β†’ [Updates: v4.38.1]
  • github/codeql-action v4.33.0@b1bff81932f5cdfc8695c7752dcee935dcd061c8 β†’ [Updates: v4.38.1]
.github/workflows/detector-version-bump-reminder.yml (2)
  • step-security/harden-runner v2.16.0@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 β†’ [Updates: v2.21.1]
  • mshick/add-pr-comment v3.9.0@ffd016c7e151d97d69d21a843022fd4cd5b96fe5 β†’ [Updates: v3.12.0]
.github/workflows/gen-docs.yml (4)
  • step-security/harden-runner v2.16.0@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 β†’ [Updates: v2.21.1]
  • actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83dd β†’ [Updates: v6.1.0, v7.0.1]
  • actions/setup-dotnet v5.2.0@c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7 β†’ [Updates: v5.4.0, v6.0.0]
  • stefanzweifel/git-auto-commit-action v7.1.0@04702edda442b2e678b25b537cec683a1493fcb9 β†’ [Updates: v7.2.0]
.github/workflows/ossf-scorecard.yml (5)
  • step-security/harden-runner v2.16.0@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 β†’ [Updates: v2.21.1]
  • actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83dd β†’ [Updates: v6.1.0, v7.0.1]
  • ossf/scorecard-action v2.4.3@4eaacf0543bb3f2c246792bd56e8cdeffafb205a β†’ [Updates: v2.4.4]
  • actions/upload-artifact v7.0.0@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f β†’ [Updates: v7.0.1]
  • github/codeql-action v4.33.0@b1bff81932f5cdfc8695c7752dcee935dcd061c8 β†’ [Updates: v4.38.1]
.github/workflows/release-drafter.yml (2)
  • step-security/harden-runner v2.16.0@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 β†’ [Updates: v2.21.1]
  • release-drafter/release-drafter v7.0.0@3a7fb5c85b80b1dda66e1ccb94009adbbd32fce3 β†’ [Updates: v7.7.0]
.github/workflows/release.yml (4)
  • step-security/harden-runner v2.16.0@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 β†’ [Updates: v2.21.1]
  • actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83dd β†’ [Updates: v6.1.0, v7.0.1]
  • actions/setup-dotnet v5.2.0@c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7 β†’ [Updates: v5.4.0, v6.0.0]
  • shogo82148/actions-upload-release-asset v1.10.0@96bc1f0cb850b65efd58a6b5eaa0a69f88d38077 β†’ [Updates: v1.10.4]
.github/workflows/smoke-test.yml (5)
  • step-security/harden-runner v2.16.0@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 β†’ [Updates: v2.21.1]
  • actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83dd β†’ [Updates: v6.1.0, v7.0.1]
  • actions/setup-dotnet v5.2.0@c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7 β†’ [Updates: v5.4.0, v6.0.0]
  • step-security/harden-runner v2.16.0@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 β†’ [Updates: v2.21.1]
  • actions/github-script v8@ed597411d8f924073f98dfc5c65a23a2325f34cd β†’ [Updates: v9]
.github/workflows/snapshot-publish.yml (6)
  • step-security/harden-runner v2.16.0@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 β†’ [Updates: v2.21.1]
  • actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83dd β†’ [Updates: v6.1.0, v7.0.1]
  • actions/setup-dotnet v5.2.0@c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7 β†’ [Updates: v5.4.0, v6.0.0]
  • actions/setup-python v6@a309ff8b426b58ec0e2a45f0f869d46889d02405 β†’ [Updates: v7, v6]
  • actions/upload-artifact v7.0.0@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f β†’ [Updates: v7.0.1]
  • python 3.14
.github/workflows/snapshot-verify.yml (7)
  • step-security/harden-runner v2.16.0@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 β†’ [Updates: v2.21.1]
  • actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83dd β†’ [Updates: v6.1.0, v7.0.1]
  • actions/github-script v8@ed597411d8f924073f98dfc5c65a23a2325f34cd β†’ [Updates: v9]
  • actions/setup-dotnet v5.2.0@c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7 β†’ [Updates: v5.4.0, v6.0.0]
  • actions/setup-python v6@a309ff8b426b58ec0e2a45f0f869d46889d02405 β†’ [Updates: v7, v6]
  • actions/upload-artifact v7.0.0@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f β†’ [Updates: v7.0.1]
  • python 3.14
.github/workflows/zizmor.yml (3)
  • step-security/harden-runner v2.16.0@fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594 β†’ [Updates: v2.21.1]
  • actions/checkout v6.0.2@de0fac2e4500dabe0009e67214ff5f5447ce83dd β†’ [Updates: v6.1.0, v7.0.1]
  • zizmorcore/zizmor-action v0.5.2@71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 β†’ [Updates: v0.6.4]
nuget (16)
Directory.Build.props
Directory.Packages.props (44)
  • System.Formats.Asn1 9.0.13 β†’ [Updates: 9.0.20, 10.0.12]
  • Valleysoft.DockerfileModel 1.2.0 β†’ [Updates: 2.0.0]
  • Faker.net 2.0.163
  • yamldotnet 16.3.0 β†’ [Updates: 18.1.0]
  • Tomlyn.Signed 0.20.0 β†’ [Updates: 2.10.1]
  • System.Threading.Tasks.Dataflow 8.0.1 β†’ [Updates: 10.0.12]
  • System.Text.Json 9.0.13 β†’ [Updates: 9.0.20, 10.0.12]
  • System.Reactive 6.1.0 β†’ [Updates: 7.0.0]
  • System.Memory 4.6.3
  • StyleCop.Analyzers 1.2.0-beta.556
  • Spectre.Console.Testing 0.54.0 β†’ [Updates: 0.57.2]
  • Spectre.Console.Cli.Extensions.DependencyInjection 0.23.0 β†’ [Updates: 0.29.0]
  • Spectre.Console.Cli 0.53.1 β†’ [Updates: 0.55.0]
  • Spectre.Console 0.54.0 β†’ [Updates: 0.57.2]
  • Serilog.Sinks.Map 2.0.0
  • Serilog.Sinks.File 7.0.0
  • Serilog.Sinks.Console 6.1.1
  • Serilog.Sinks.Async 2.1.0
  • Serilog.Extensions.Logging 8.0.0 β†’ [Updates: 10.0.0]
  • Serilog 4.3.1 β†’ [Updates: 4.4.0]
  • SemanticVersioning 2.0.2 β†’ [Updates: 3.0.0]
  • Polly 8.6.6 β†’ [Updates: 8.8.0]
  • packageurl-dotnet 2.0.0 β†’ [Updates: 2.0.1]
  • NuGet.Versioning 7.3.0 β†’ [Updates: 7.9.0]
  • NuGet.ProjectModel 7.3.0 β†’ [Updates: 7.9.0]
  • Newtonsoft.Json.Schema 4.0.1
  • Newtonsoft.Json 13.0.4
  • MSTest.Analyzers 4.1.0 β†’ [Updates: 4.4.1]
  • MSTest.TestFramework 4.1.0 β†’ [Updates: 4.4.1]
  • morelinq 4.4.0
  • Moq 4.18.4 β†’ [Updates: 4.20.72]
  • MinVer 7.0.0 β†’ [Updates: 8.0.0]
  • Microsoft.Extensions.FileSystemGlobbing 8.0.0 β†’ [Updates: 10.0.12]
  • Microsoft.VisualStudio.Threading.Analyzers 17.14.15 β†’ [Updates: 18.7.23]
  • MSBuild.StructuredLogger 2.3.113 β†’ [Updates: 2.3.246]
  • Microsoft.SourceLink.GitHub 8.0.0 β†’ [Updates: 10.0.401]
  • Microsoft.Extensions.Logging 8.0.1 β†’ [Updates: 10.0.12]
  • Microsoft.Extensions.Http 8.0.1 β†’ [Updates: 10.0.12]
  • Microsoft.Extensions.DependencyInjection.Abstractions 8.0.2 β†’ [Updates: 10.0.12]
  • Microsoft.Extensions.DependencyInjection 8.0.1 β†’ [Updates: 10.0.12]
  • Microsoft.Extensions.Caching.Memory 8.0.1 β†’ [Updates: 10.0.12]
  • AwesomeAssertions.Analyzers 9.0.8
  • AwesomeAssertions 9.4.0 β†’ [Updates: 9.6.0]
  • Docker.DotNet 3.125.15
global.json (2)
  • dotnet-sdk 8.0.418 β†’ [Updates: 8.0.425, 10.0.401]
  • MSTest.Sdk 4.1.0 β†’ [Updates: 4.4.1]
src/Directory.Build.props
src/Microsoft.ComponentDetection.Common/Microsoft.ComponentDetection.Common.csproj
src/Microsoft.ComponentDetection.Contracts/Microsoft.ComponentDetection.Contracts.csproj
src/Microsoft.ComponentDetection.Detectors/Microsoft.ComponentDetection.Detectors.csproj
src/Microsoft.ComponentDetection.Orchestrator/Microsoft.ComponentDetection.Orchestrator.csproj
src/Microsoft.ComponentDetection/Microsoft.ComponentDetection.csproj
test/Directory.Build.props
test/Microsoft.ComponentDetection.Common.Tests/Microsoft.ComponentDetection.Common.Tests.csproj
test/Microsoft.ComponentDetection.Contracts.Tests/Microsoft.ComponentDetection.Contracts.Tests.csproj
test/Microsoft.ComponentDetection.Detectors.Tests/Microsoft.ComponentDetection.Detectors.Tests.csproj
test/Microsoft.ComponentDetection.Orchestrator.Tests/Microsoft.ComponentDetection.Orchestrator.Tests.csproj
test/Microsoft.ComponentDetection.TestsUtilities/Microsoft.ComponentDetection.TestsUtilities.csproj
test/Microsoft.ComponentDetection.VerificationTests/Microsoft.ComponentDetection.VerificationTests.csproj

  • Check this box to trigger a request for Renovate to run again on this repository

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up β€” it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Read the linked Renovate Dependency Dashboard documentation first. Review the update entries in .devcontainer/devcontainer.json, Dockerfile, and the listed .github/workflows files, then use the relevant checkbox to request a rate-limited update. Done means the selected dependency update is created and its resulting pull request passes the repository checks.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp, docker, github-actions
Domain
build-system, ci-cd, devops
Issue type
Refactor
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.