Skip to content

Bump WolverineFx and WolverineFx.RuntimeCompilation - #2384

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/nuget/multi-8ba789dcf8
Open

Bump WolverineFx and WolverineFx.RuntimeCompilation#2384
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/nuget/multi-8ba789dcf8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor

Updated WolverineFx from 6.31.0 to 6.33.0.

Release notes

Sourced from WolverineFx's releases.

6.33.0

The headline is a new package. WolverineFx.AI makes a one shot LLM call an ordinary Wolverine message: durable, outbox enrolled, retried by the same rules as everything else, and testable without a model anywhere in sight.

WolverineFx.AI (new package)

An LlmCallout is a message. Return one from a handler next to your storage action and it is enrolled in that handler's outbox, so a callout cannot fire for a transaction that did not commit and cannot be lost to a restart in between. The model's answer comes back as an ordinary cascading message, with an ordinary handler, an ordinary retry policy, and its own place in the correlation chain. (closes #​4227)

  • Spend guardrails as middleware on the callout queue. LlmBudget.MaximumPromptCharacters refuses a runaway prompt before your provider is ever called; MaximumTokensPerWindow refuses callouts once the node has burned its allowance. Both dead letter rather than retry, and so does an answer that cannot be parsed into the response type you asked for -- retrying either is the runaway spend the budget exists to stop.
  • A scripted IChatClient for testing. StubChatClient exercises a callout's whole round trip with no key, no network and no model.
  • Trim and AOT clean, guarded by a Wolverine.AI.AotSmoke project under TrimMode=full that CI runs. (closes #​4230)
  • Documentation for tuning it, new in this release: how to control parallelism against your provider, why the answer has its own queue with its own settings, and how to bring your own error handling on both sides.

The package references only the Microsoft.Extensions.AI abstractions, never a vendor SDK. The provider -- Anthropic, OpenAI, Azure, Ollama -- and any middleware over it stay your choice.

Fixes

  • A node no longer sweeps up its own in-flight stop as a wedged shard. An event-subscription agent could end up running on two nodes at once while wolverine_nodes credited only one, so nothing in the system could ever stop the extra copy. (closes #​4240)
  • Node record descriptions no longer overflow the column and fail the insert. An AssignmentChanged description carries an agent URI, a schema name and a destination node, which on a real cluster overran the description column and failed the whole AgentCommand batch behind it. MySQL was worst hit at VARCHAR(255). (closes #​4246)
  • DataAnnotations validation works with ServiceLocationPolicy.NotAllowed -- on HTTP endpoints and, now, on message handlers. Under the Wolverine 6 default this made the validation middleware unusable and threw at bootstrap. (closes #​4238)
  • A failed EF Core rollback no longer displaces the exception that caused it. (closes #​4239)
  • Wolverine parameter attributes work on gRPC before/after hooks -- [Entity], [All], [Queryable], [WriteAggregate] and the rest. (closes #​3935)
  • An application-wide default duplicate status code via opts.DefaultDuplicateStatusCode, and deduplication refusals now advertise their problem document in OpenAPI.
  • Concurrent IHost.StopAsync no longer tears the agents down twice.

Upgrade note

6.33.0 requires Weasel 9.30.0, and that raises the GH-4246 fix from "new databases only" to "existing ones too": the schema differ now compares character lengths, so a widened varchar is no longer invisible to it and an existing table is corrected in place by an ALTER TABLE ... MODIFY that keeps its rows.

Worth knowing before you upgrade: that comparison runs in both directions. Width drift that was previously invisible now generates ALTERs, and a model narrower than an existing column will emit a narrowing ALTER that can fail on real data. Sizes that are not character lengths -- a MySQL int(11) display width, a decimal precision, a datetime fsp -- are still ignored.

Dependencies

JasperFx 2.60.0, Marten 9.30.0, Polecat 5.21.1, Fisher 1.0.6, Weasel 9.30.0.

6.32.0

See CHANGELOG.md for the full entries.

New packages

WolverineFx.AmazonS3 and WolverineFx.AzureBlobStorage carry document and saga persistence plus the claim check store that used to ship separately. Registration is explicit per type — Store<T>() and Saga<T>() are separate calls and each refuses the other's type — and saga writes are guarded by conditional requests, surfacing as SagaConcurrencyException so one OnException<ConcurrencyException> policy still covers every store. (#​4160, originally #​4165 by Anne Erdtsieck.)

WolverineFx.ClaimCheck.AmazonS3 is deprecated. The namespace is unchanged, so migration is a package reference swap — but keeping both referenced produces ambiguous-type errors.

Redis document and saga persistence folds into the existing WolverineFx.Redis rather than a new package, with saga concurrency implemented as a Lua compare-and-swap.

Fixes

  • A shutting-down node no longer dead-letters work whose handler never ran (#​4213). Core, so every transport.
  • Scheduled promotion matches the whole message identity on SQLite, SQL Server, MySQL and Oracle rather than PostgreSQL alone (#​4216) — including a not-yet-due scheduled message being promoted and executed early.
  • A redelivered inbox row can be retired when its identity is already handled under EnableInboxPartitioning (#​4216); previously it could not be retired at all.
  • A listener whose broker entity was deleted underneath it now heals instead of retrying once a second forever (#​4215).
  • Terminal settle failures are classified on the retry block, closing a gap where two of four Azure Service Bus listeners had no classification at all (#​4012).
  • Scope priming no longer manufactures a Marten session for every handler that service-locates anything (#​4198). Requires JasperFx 2.58.0 or later.
  • A duplicated scheduled identity no longer wedges promotion on a partitioned PostgreSQL inbox (#​4202).
  • AddStopConditionIfNull accepts the null identity its signature declares (#​4161).

Diagnostics

  • NativeAck and partitioned listeners report ceilings, per-lane depth and duplicate-suppression counts (#​4199). BufferLimit is now null on the modes that never enforced it, with the broker's prefetch window reported as InFlightLimit.
  • MaximumBrokerRedeliveries is documented as the delivery count it actually is (#​4216). Behaviour unchanged.

Event model

  • A stream-appending handler's return value is reported as a reply rather than an emitted event (#​4204).
  • A generic message type's slice reads the way source spells it, which also stops two relays with different payloads colliding on one slice (#​4205).

Also

  • Explicit per-provider entity attributes, starting with [FromMarten] and [FromEfCore] (#​4214).
  • RabbitMQ documentation for AddResourceSetupOnStartup and AutoProvision (#​4223).

Commits viewable in compare view.

Updated WolverineFx.RuntimeCompilation from 6.31.0 to 6.33.0.

Release notes

Sourced from WolverineFx.RuntimeCompilation's releases.

6.33.0

The headline is a new package. WolverineFx.AI makes a one shot LLM call an ordinary Wolverine message: durable, outbox enrolled, retried by the same rules as everything else, and testable without a model anywhere in sight.

WolverineFx.AI (new package)

An LlmCallout is a message. Return one from a handler next to your storage action and it is enrolled in that handler's outbox, so a callout cannot fire for a transaction that did not commit and cannot be lost to a restart in between. The model's answer comes back as an ordinary cascading message, with an ordinary handler, an ordinary retry policy, and its own place in the correlation chain. (closes #​4227)

  • Spend guardrails as middleware on the callout queue. LlmBudget.MaximumPromptCharacters refuses a runaway prompt before your provider is ever called; MaximumTokensPerWindow refuses callouts once the node has burned its allowance. Both dead letter rather than retry, and so does an answer that cannot be parsed into the response type you asked for -- retrying either is the runaway spend the budget exists to stop.
  • A scripted IChatClient for testing. StubChatClient exercises a callout's whole round trip with no key, no network and no model.
  • Trim and AOT clean, guarded by a Wolverine.AI.AotSmoke project under TrimMode=full that CI runs. (closes #​4230)
  • Documentation for tuning it, new in this release: how to control parallelism against your provider, why the answer has its own queue with its own settings, and how to bring your own error handling on both sides.

The package references only the Microsoft.Extensions.AI abstractions, never a vendor SDK. The provider -- Anthropic, OpenAI, Azure, Ollama -- and any middleware over it stay your choice.

Fixes

  • A node no longer sweeps up its own in-flight stop as a wedged shard. An event-subscription agent could end up running on two nodes at once while wolverine_nodes credited only one, so nothing in the system could ever stop the extra copy. (closes #​4240)
  • Node record descriptions no longer overflow the column and fail the insert. An AssignmentChanged description carries an agent URI, a schema name and a destination node, which on a real cluster overran the description column and failed the whole AgentCommand batch behind it. MySQL was worst hit at VARCHAR(255). (closes #​4246)
  • DataAnnotations validation works with ServiceLocationPolicy.NotAllowed -- on HTTP endpoints and, now, on message handlers. Under the Wolverine 6 default this made the validation middleware unusable and threw at bootstrap. (closes #​4238)
  • A failed EF Core rollback no longer displaces the exception that caused it. (closes #​4239)
  • Wolverine parameter attributes work on gRPC before/after hooks -- [Entity], [All], [Queryable], [WriteAggregate] and the rest. (closes #​3935)
  • An application-wide default duplicate status code via opts.DefaultDuplicateStatusCode, and deduplication refusals now advertise their problem document in OpenAPI.
  • Concurrent IHost.StopAsync no longer tears the agents down twice.

Upgrade note

6.33.0 requires Weasel 9.30.0, and that raises the GH-4246 fix from "new databases only" to "existing ones too": the schema differ now compares character lengths, so a widened varchar is no longer invisible to it and an existing table is corrected in place by an ALTER TABLE ... MODIFY that keeps its rows.

Worth knowing before you upgrade: that comparison runs in both directions. Width drift that was previously invisible now generates ALTERs, and a model narrower than an existing column will emit a narrowing ALTER that can fail on real data. Sizes that are not character lengths -- a MySQL int(11) display width, a decimal precision, a datetime fsp -- are still ignored.

Dependencies

JasperFx 2.60.0, Marten 9.30.0, Polecat 5.21.1, Fisher 1.0.6, Weasel 9.30.0.

6.32.0

See CHANGELOG.md for the full entries.

New packages

WolverineFx.AmazonS3 and WolverineFx.AzureBlobStorage carry document and saga persistence plus the claim check store that used to ship separately. Registration is explicit per type — Store<T>() and Saga<T>() are separate calls and each refuses the other's type — and saga writes are guarded by conditional requests, surfacing as SagaConcurrencyException so one OnException<ConcurrencyException> policy still covers every store. (#​4160, originally #​4165 by Anne Erdtsieck.)

WolverineFx.ClaimCheck.AmazonS3 is deprecated. The namespace is unchanged, so migration is a package reference swap — but keeping both referenced produces ambiguous-type errors.

Redis document and saga persistence folds into the existing WolverineFx.Redis rather than a new package, with saga concurrency implemented as a Lua compare-and-swap.

Fixes

  • A shutting-down node no longer dead-letters work whose handler never ran (#​4213). Core, so every transport.
  • Scheduled promotion matches the whole message identity on SQLite, SQL Server, MySQL and Oracle rather than PostgreSQL alone (#​4216) — including a not-yet-due scheduled message being promoted and executed early.
  • A redelivered inbox row can be retired when its identity is already handled under EnableInboxPartitioning (#​4216); previously it could not be retired at all.
  • A listener whose broker entity was deleted underneath it now heals instead of retrying once a second forever (#​4215).
  • Terminal settle failures are classified on the retry block, closing a gap where two of four Azure Service Bus listeners had no classification at all (#​4012).
  • Scope priming no longer manufactures a Marten session for every handler that service-locates anything (#​4198). Requires JasperFx 2.58.0 or later.
  • A duplicated scheduled identity no longer wedges promotion on a partitioned PostgreSQL inbox (#​4202).
  • AddStopConditionIfNull accepts the null identity its signature declares (#​4161).

Diagnostics

  • NativeAck and partitioned listeners report ceilings, per-lane depth and duplicate-suppression counts (#​4199). BufferLimit is now null on the modes that never enforced it, with the broker's prefetch window reported as InFlightLimit.
  • MaximumBrokerRedeliveries is documented as the delivery count it actually is (#​4216). Behaviour unchanged.

Event model

  • A stream-appending handler's return value is reported as a reply rather than an emitted event (#​4204).
  • A generic message type's slice reads the way source spells it, which also stops two relays with different payloads colliding on one slice (#​4205).

Also

  • Explicit per-provider entity attributes, starting with [FromMarten] and [FromEfCore] (#​4214).
  • RabbitMQ documentation for AddResourceSetupOnStartup and AutoProvision (#​4223).

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps WolverineFx from 6.31.0 to 6.33.0
Bumps WolverineFx.RuntimeCompilation from 6.31.0 to 6.33.0

---
updated-dependencies:
- dependency-name: WolverineFx
  dependency-version: 6.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: WolverineFx.RuntimeCompilation
  dependency-version: 6.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment