Skip to content

[Dependencies] Updating Meziantou.Analyzer (Code Analysis) to 3.0.177 - #179

Merged
credfeto merged 3 commits into
mainfrom
depends/update-meziantou.analyzer/3.0.177
Aug 28, 2026
Merged

credfeto merged 3 commits into
mainfrom
depends/update-meziantou.analyzer/3.0.177

Conversation

@dnyw4l3n13

Copy link
Copy Markdown
Collaborator

Description

How Has This Been Tested

  • All unit tests pass.
  • All integration tests pass.
  • Manual Testing:

Types of changes

  • Docs change
  • Refactoring
  • Dependency upgrade
  • Additional Unit Tests\Integration Tests
  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing
    functionality to change)
  • Removed no-longer used code

Deployment Configuration Changes

  • Requires deployment configuration changes as specified below and in CHANGELOG.md

Checklist

  • I have added tests to cover my changes.
  • Unreleased section of CHANGELOG.md has been updated with details of this PR.
  • No user-controlled or step-output value is string-interpolated directly into a run:/script: body (workflow or composite action); pass it via step-level env: and reference $VAR (bash) or process.env.VAR (github-script) instead.

@dnyw4l3n13 dnyw4l3n13 added the auto-pr Pull request created automatically label Aug 23, 2026
@credfeto

credfeto commented Aug 23, 2026 •

Copy link
Copy Markdown
Owner

Roslyn analyzer findings

Source Rule Level File Line Suppressed Message
DotNet CA2100 error src/Credfeto.Database.Migrations/MigrationTrackerBase.cs 62 yes Review if the query string passed to 'string DbCommand.CommandText' in 'EnsureCreatedAsync', accepts any user input
DotNet CA2100 error src/Credfeto.Database.Migrations/MigrationTrackerBase.cs 82 yes Review if the query string passed to 'string DbCommand.CommandText' in 'GetAppliedMigrationIdsAsync', accepts any user input
DotNet CA2100 error src/Credfeto.Database.Migrations/MigrationTrackerBase.cs 114 yes Review if the query string passed to 'string DbCommand.CommandText' in 'RecordAppliedAsync', accepts any user input
DotNet CA2100 error src/Credfeto.Database.Migrations/MigrationRunner.cs 103 yes Review if the query string passed to 'string DbCommand.CommandText' in 'ApplyMigrationAsync', accepts any user input
DotNet CA1010 error src/Credfeto.Database.Migrations.TestHelpers/FakeDbDataReader.cs 14 yes Type 'FakeDbDataReader' directly or indirectly inherits 'IEnumerable' without implementing 'IEnumerable'. Publicly-visible types should implement the generic version to broaden usability.
DotNet CA1010 error src/Credfeto.Database.Migrations.TestHelpers/FakeDbParameterCollection.cs 15 yes Type 'FakeDbParameterCollection' directly or indirectly inherits 'IList' without implementing any of 'IList', 'IReadOnlyList'. Publicly-visible types should implement the generic version to broaden usability.
DotNet MA0051 error src/Credfeto.Database.Source.Generation/Receivers/DatabaseSyntaxReceiver.cs 179 yes Method is too long (87 lines; maximum allowed: 60)
DotNet RCS1231 error src/Credfeto.Database.Source.Generation/Receivers/DatabaseSyntaxReceiver.cs 367 yes Make parameter ref read-only
DotNet PH2071 error src/Credfeto.Database.Source.Generation/Helpers/ExtractColumns.cs 9 yes Duplicate shape found at ExtractColumns.cs line 51 character 5. Refactor logic or exempt duplication. Duplicate shape details: "{ return Identifier switch { StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier"
DotNet S3267 error src/Credfeto.Database.Source.Generation/Extensions/EnumerableExtensions.cs 16 yes Loops should be simplified using the "Where" LINQ method
DotNet CSE007 error src/Credfeto.Database.Source.Generation.Example/Mappers/AccountIdListMapper.cs 57 yes Handle disposal correctly
DotNet MA0051 error src/Credfeto.Database.SqlServer/SqlServerDatabase.cs 44 yes Method is too long (80 lines; maximum allowed: 60)

@dnyw4l3n13
dnyw4l3n13 force-pushed the depends/update-meziantou.analyzer/3.0.177 branch from 50c458c to 29f1b03 Compare August 24, 2026 23:51
@dnyw4l3n13

Copy link
Copy Markdown
Collaborator Author

Diagnosis

Root cause of the build-pre-release failure: Meziantou.Analyzer 3.0.177 adds/tightens MA0002 (require an explicit IEqualityComparer<string>/IComparer<string> overload), which now flags AppMigrationsTests.cs:25:

Assert.Equal(
    ["create_accounts", "add_email_column", "create_email_index"],
    migrations.Select(static migration => migration.Name),
    StringComparer.Ordinal
);

(adds the StringComparer.Ordinal argument, matching the pattern already used elsewhere in this suite, e.g. SqlObjectMapAttributeTests.cs:18). Verified: a full-solution dotnet build -c Release is clean (0 warnings, 0 errors) with this change, and the project's 5 tests pass.

Blocker - this fix cannot be committed right now. This repo's pre-commit hook chain runs dotnet buildcheck, which currently reports 57 errors (Package X is missing IncludeAssets (expected compile;runtime), Should use package xunit.v3.aot.mtp-v2 rather than xunit.v3.mtp-v2) across nearly every project. I confirmed these are not introduced by this PR: they reproduce identically against origin/main at commit 143e6902 (with the old Meziantou.Analyzer 3.0.122). CI installs FunFair.BuildCheck unpinned at latest (.github/actions/dotnet-build-check/action.yml), and main's last CI run (32721253659, 2026-08-24T11:19) succeeded in 5m33s with buildcheck as its first dotnet step - so the tool version baked into this session's container (474.2.12.2590) is enforcing rules that CI's latest did not enforce as of main's last green run. A newer FunFair.BuildCheck release appears to have shipped between then and now, introducing these two new rules repo-wide.

I can't commit the MA0002 fix through the normal path: skipping the pre-commit hook (--no-verify) isn't permitted, and hand-fixing 57 unrelated IncludeAssets/package-name entries across 19 project files inside this dependency-bump PR is out of scope and unverifiable from here (no existing IncludeAssets="compile;runtime" precedent in this repo to copy, and I can't confirm xunit.v3.aot.mtp-v2 resolves at the same 4.0.0 version without a working restore).

Requesting a decision: either pin FunFair.BuildCheck to a known-good version, or land a dedicated baseline-fix PR for the 57 findings so this and other in-flight dependency PRs can commit again.

The verified MA0002 fix above is staged locally on this branch but not yet committed.

@dnyw4l3n13 dnyw4l3n13 added the Blocked Blocked by a dependency or external factor label Aug 25, 2026
@credfeto credfeto removed the Blocked Blocked by a dependency or external factor label Aug 28, 2026
…er 3.0.177)

Meziantou.Analyzer 3.0.177 newly flags Assert.Equal comparing string
sequences without an explicit IEqualityComparer<string>.

Dependencies - Updated Meziantou.Analyzer to 3.0.177
@credfeto
credfeto force-pushed the depends/update-meziantou.analyzer/3.0.177 branch from 29f1b03 to 5e33265 Compare August 28, 2026 13:59
@dnyw4l3n13

Copy link
Copy Markdown
Collaborator Author

Rebase onto origin/main hit merge conflicts outside the scope this session is allowed to resolve automatically (PHASE A only auto-resolves CHANGELOG.md and COVERAGE.md conflicts). Stopping here for a human decision; the rebase has been aborted and the branch left unchanged.

Conflicting files (13 total):

  • CHANGELOG.md - routine, would normally be resolved by keeping entries from both sides.
  • 12 .csproj files, all with the same two-line conflict pattern:
    • src/Credfeto.Database.Interfaces/Credfeto.Database.Interfaces.csproj
    • src/Credfeto.Database.Migrations.Pgsql/Credfeto.Database.Migrations.Pgsql.csproj
    • src/Credfeto.Database.Migrations.Source.Generation.Example/Credfeto.Database.Migrations.Source.Generation.Example.csproj
    • src/Credfeto.Database.Migrations.Source.Generation/Credfeto.Database.Migrations.Source.Generation.csproj
    • src/Credfeto.Database.Migrations.SqlServer/Credfeto.Database.Migrations.SqlServer.csproj
    • src/Credfeto.Database.Migrations.TestHelpers/Credfeto.Database.Migrations.TestHelpers.csproj
    • src/Credfeto.Database.Migrations/Credfeto.Database.Migrations.csproj
    • src/Credfeto.Database.Pgsql/Credfeto.Database.Pgsql.csproj
    • src/Credfeto.Database.Source.Generation.Example/Credfeto.Database.Source.Generation.Example.csproj
    • src/Credfeto.Database.Source.Generation/Credfeto.Database.Source.Generation.csproj
    • src/Credfeto.Database.SqlServer/Credfeto.Database.SqlServer.csproj
    • src/Credfeto.Database/Credfeto.Database.csproj

The pattern, identical in every file:

<<<<<<< HEAD (origin/main)
    <PackageReference Include="FunFair.CodeAnalysis" Version="7.2.13.2323" .../>
    <PackageReference Include="Meziantou.Analyzer" Version="3.0.122" .../>
=======
    <PackageReference Include="FunFair.CodeAnalysis" Version="7.2.7.2152" .../>
    <PackageReference Include="Meziantou.Analyzer" Version="3.0.177" .../>
>>>>>>> 29f1b03d6 (this PR's own commit: Updating Meziantou.Analyzer to 3.0.177)

origin/main has independently bumped FunFair.CodeAnalysis to 7.2.13.2323 since this PR branched, while this PR's own commit still carries the older 7.2.7.2152 alongside its Meziantou.Analyzer bump to 3.0.177. Neither side is simply "newer" - each side advanced a different package.

Useful data point: the sibling *.Tests project files (e.g. Credfeto.Database.Interfaces.Tests.csproj) have the same two PackageReference lines but non-adjacent in the file, so git auto-merged them without a conflict - and the auto-merged result is FunFair.CodeAnalysis 7.2.13.2323 + Meziantou.Analyzer 3.0.177, i.e. the newer version of each package independently. That is the recommended resolution for the 12 conflicting files above, for a human to confirm - not a wholesale --ours/--theirs, which would either lose the FunFair.CodeAnalysis bump (theirs) or lose this PR's own Meziantou.Analyzer bump (ours), and would also leave the library projects inconsistent with the already-merged .Tests projects.

Separately, and still unresolved: dnyw4l3n13's 2026-08-25 comment flagged that this PR's actual MA0002 fix (in AppMigrationsTests.cs) can't be committed because the pre-commit dotnet buildcheck step currently reports 57 pre-existing, unrelated errors repo-wide (reproducing identically against origin/main), and asked for a decision: pin FunFair.BuildCheck to a known-good version, or land a dedicated baseline-fix PR. That still needs a human answer regardless of how the conflict above is resolved.

No coverage regression; figures unchanged from main's baseline (91.4% overall).
@credfeto

Copy link
Copy Markdown
Owner

Coverage ratchet passed - advancing to Human Review

@credfeto
credfeto marked this pull request as ready for review August 28, 2026 14:20
@credfeto
credfeto enabled auto-merge August 28, 2026 14:20
@dnyw4l3n13

Copy link
Copy Markdown
Collaborator Author

Simplify clean - advancing to code review

(Also closing the loop on the two earlier status comments: the FunFair.CodeAnalysis/Meziantou.Analyzer rebase conflict was resolved in 13170e7 taking the newer version of each package, and the MA0002 fix landed in 5e33265; CI's build-pre-release now passes cleanly and the previously reported local buildcheck failures do not reproduce, so no FunFair.BuildCheck pin is needed.)

@credfeto
credfeto merged commit 9e6f959 into main Aug 28, 2026
31 of 42 checks passed
@credfeto
credfeto deleted the depends/update-meziantou.analyzer/3.0.177 branch August 28, 2026 14:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-pr Pull request created automatically

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants