Skip to content

Bump Microsoft.CodeAnalysis.CSharp from 5.3.0 to 5.6.0 - #55

Merged
ldsenow merged 1 commit into
mainfrom
dependabot/nuget/src/HeroParser.Generators/multi-fc18b8fd9f
Jul 7, 2026
Merged

Bump Microsoft.CodeAnalysis.CSharp from 5.3.0 to 5.6.0#55
ldsenow merged 1 commit into
mainfrom
dependabot/nuget/src/HeroParser.Generators/multi-fc18b8fd9f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 6, 2026

Copy link
Copy Markdown
Contributor

Updated Microsoft.CodeAnalysis.CSharp from 5.3.0 to 5.6.0.

Release notes

Sourced from Microsoft.CodeAnalysis.CSharp's releases.

No release notes found for this version range.

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

---
updated-dependencies:
- dependency-name: Microsoft.CodeAnalysis.CSharp
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: Microsoft.CodeAnalysis.CSharp
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 6, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: security. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 6, 2026
@github-actions

github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

⚠️ Deprecation Warning: The deny-licenses option is deprecated for possible removal in the next major release. For more information, see issue 997.

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 2 package(s) with unknown licenses.
See the Details below.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA 4ae9d3d.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

License Issues

src/HeroParser.Generators/HeroParser.Generators.csproj

PackageVersionLicenseIssue Type
Microsoft.CodeAnalysis.CSharp5.6.0NullUnknown License

tests/HeroParser.Generators.Tests/HeroParser.Generators.Tests.csproj

PackageVersionLicenseIssue Type
Microsoft.CodeAnalysis.CSharp5.6.0NullUnknown License
Denied Licenses: GPL-2.0, GPL-3.0, AGPL-3.0

OpenSSF Scorecard

PackageVersionScoreDetails
nuget/Microsoft.CodeAnalysis.CSharp 5.6.0 🟢 5.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1030 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy🟢 10security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Binary-Artifacts⚠️ 0binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing⚠️ 0project is not fuzzed
nuget/Microsoft.CodeAnalysis.CSharp 5.6.0 🟢 5.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1030 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy🟢 10security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Binary-Artifacts⚠️ 0binaries present in source code
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing⚠️ 0project is not fuzzed

Scanned Files

  • src/HeroParser.Generators/HeroParser.Generators.csproj
  • tests/HeroParser.Generators.Tests/HeroParser.Generators.Tests.csproj

@github-actions

github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

Benchmark Results (net10.0)


BenchmarkDotNet v0.15.8, Linux Ubuntu 24.04.4 LTS (Noble Numbat)
AMD EPYC 7763 2.45GHz, 1 CPU, 4 logical and 2 physical cores
.NET SDK 10.0.301
  [Host]     : .NET 10.0.9 (10.0.9, 10.0.926.27113), X64 RyuJIT x86-64-v3
  Job-INMAZI : .NET 10.0.9 (10.0.9, 10.0.926.27113), X64 RyuJIT x86-64-v3

IterationCount=5  RunStrategy=Throughput  WarmupCount=3  

Method Rows Columns Mean Error StdDev Ratio RatioSD Allocated Alloc Ratio
ParseCsvUtf8 1000 10 72.14 μs 0.186 μs 0.029 μs 1.00 0.00 32 B 1.00
ParseCsvUtf16Scalar 1000 10 74.21 μs 0.179 μs 0.028 μs 1.03 0.00 32 B 1.00
ParseCsvUtf8 1000 25 126.80 μs 0.356 μs 0.055 μs 1.00 0.00 32 B 1.00
ParseCsvUtf16Scalar 1000 25 140.54 μs 0.353 μs 0.055 μs 1.11 0.00 32 B 1.00
ParseCsvUtf8 1000 100 410.23 μs 0.415 μs 0.064 μs 1.00 0.00 32 B 1.00
ParseCsvUtf16Scalar 1000 100 486.40 μs 1.676 μs 0.259 μs 1.19 0.00 32 B 1.00
ParseCsvUtf8 10000 10 736.15 μs 3.786 μs 0.586 μs 1.00 0.00 32 B 1.00
ParseCsvUtf16Scalar 10000 10 828.17 μs 1.251 μs 0.325 μs 1.13 0.00 32 B 1.00
ParseCsvUtf8 10000 25 1,319.17 μs 3.660 μs 0.951 μs 1.00 0.00 32 B 1.00
ParseCsvUtf16Scalar 10000 25 1,456.94 μs 7.061 μs 1.834 μs 1.10 0.00 32 B 1.00
ParseCsvUtf8 10000 100 4,612.24 μs 19.771 μs 5.134 μs 1.00 0.00 32 B 1.00
ParseCsvUtf16Scalar 10000 100 4,912.07 μs 48.506 μs 7.506 μs 1.07 0.00 32 B 1.00
ParseCsvUtf8 100000 10 7,500.45 μs 52.167 μs 13.548 μs 1.00 0.00 32 B 1.00
ParseCsvUtf16Scalar 100000 10 7,970.64 μs 49.538 μs 7.666 μs 1.06 0.00 32 B 1.00
ParseCsvUtf8 100000 25 13,502.54 μs 25.660 μs 3.971 μs 1.00 0.00 32 B 1.00
ParseCsvUtf16Scalar 100000 25 15,363.72 μs 56.231 μs 8.702 μs 1.14 0.00 32 B 1.00
ParseCsvUtf8 100000 100 44,190.79 μs 853.915 μs 132.144 μs 1.00 0.00 32 B 1.00
ParseCsvUtf16Scalar 100000 100 80,653.43 μs 65,610.768 μs 17,038.908 μs 1.83 0.35 32 B 1.00

@github-actions

github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

Test Results (ubuntu-latest - net10.0)

3 270 tests  ±0   3 270 ✅ ±0   40s ⏱️ -1s
    2 suites ±0       0 💤 ±0 
    2 files   ±0       0 ❌ ±0 

Results for commit 4ae9d3d. ± Comparison against base commit f31e84c.

@ldsenow
ldsenow merged commit 2469f0d into main Jul 7, 2026
34 checks passed
@ldsenow
ldsenow deleted the dependabot/nuget/src/HeroParser.Generators/multi-fc18b8fd9f branch July 7, 2026 00:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant