Skip to content

[Dependencies] Updating Microsoft.CodeAnalysis.CSharp (Code Analysis) to 5.9.0 - #180

Merged
dnyw4l3n13 merged 4 commits into
mainfrom
depends/update-microsoft.codeanalysis.csharp/5.9.0
Aug 26, 2026
Merged

dnyw4l3n13 merged 4 commits into
mainfrom
depends/update-microsoft.codeanalysis.csharp/5.9.0

Conversation

@dnyw4l3n13

Copy link
Copy Markdown
Collaborator

Description

How Has This Been Tested

  • All unit tests pass.
  • All integration tests pass.
  • Manual Testing:

Types of changes

  • Docs change
  • Refactoring
  • Dependency upgrade
  • Additional Unit Tests\Integration Tests
  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing
    functionality to change)
  • Removed no-longer used code

Deployment Configuration Changes

  • Requires deployment configuration changes as specified below and in CHANGELOG.md

Checklist

  • I have added tests to cover my changes.
  • Unreleased section of CHANGELOG.md has been updated with details of this PR.
  • No user-controlled or step-output value is string-interpolated directly into a run:/script: body (workflow or composite action); pass it via step-level env: and reference $VAR (bash) or process.env.VAR (github-script) instead.

@dnyw4l3n13 dnyw4l3n13 added the auto-pr Pull request created automatically label Aug 23, 2026
@credfeto

credfeto commented Aug 23, 2026 •

Copy link
Copy Markdown
Owner

Roslyn analyzer findings

Source Rule Level File Line Suppressed Message
DotNet CA2100 error src/Credfeto.Database.Migrations/MigrationTrackerBase.cs 62 yes Review if the query string passed to 'string DbCommand.CommandText' in 'EnsureCreatedAsync', accepts any user input
DotNet CA2100 error src/Credfeto.Database.Migrations/MigrationTrackerBase.cs 82 yes Review if the query string passed to 'string DbCommand.CommandText' in 'GetAppliedMigrationIdsAsync', accepts any user input
DotNet CA2100 error src/Credfeto.Database.Migrations/MigrationTrackerBase.cs 114 yes Review if the query string passed to 'string DbCommand.CommandText' in 'RecordAppliedAsync', accepts any user input
DotNet CA2100 error src/Credfeto.Database.Migrations/MigrationRunner.cs 103 yes Review if the query string passed to 'string DbCommand.CommandText' in 'ApplyMigrationAsync', accepts any user input
DotNet CA1010 error src/Credfeto.Database.Migrations.TestHelpers/FakeDbDataReader.cs 14 yes Type 'FakeDbDataReader' directly or indirectly inherits 'IEnumerable' without implementing 'IEnumerable'. Publicly-visible types should implement the generic version to broaden usability.
DotNet CA1010 error src/Credfeto.Database.Migrations.TestHelpers/FakeDbParameterCollection.cs 15 yes Type 'FakeDbParameterCollection' directly or indirectly inherits 'IList' without implementing any of 'IList', 'IReadOnlyList'. Publicly-visible types should implement the generic version to broaden usability.
DotNet MA0051 error src/Credfeto.Database.Source.Generation/Receivers/DatabaseSyntaxReceiver.cs 179 yes Method is too long (87 lines; maximum allowed: 60)
DotNet RCS1231 error src/Credfeto.Database.Source.Generation/Receivers/DatabaseSyntaxReceiver.cs 367 yes Make parameter ref read-only
DotNet S3267 error src/Credfeto.Database.Source.Generation/Extensions/EnumerableExtensions.cs 16 yes Loops should be simplified using the "Where" LINQ method
DotNet PH2071 error src/Credfeto.Database.Source.Generation/Helpers/ExtractColumns.cs 51 yes Duplicate shape found at ExtractColumns.cs line 9 character 5. Refactor logic or exempt duplication. Duplicate shape details: "{ return Identifier switch { StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier : Identifier ) , StringLiteral => Identifier ( Identifier"
DotNet CSE007 error src/Credfeto.Database.Source.Generation.Example/Mappers/AccountIdListMapper.cs 57 yes Handle disposal correctly
DotNet MA0051 error src/Credfeto.Database.SqlServer/SqlServerDatabase.cs 44 yes Method is too long (80 lines; maximum allowed: 60)

@dnyw4l3n13
dnyw4l3n13 force-pushed the depends/update-microsoft.codeanalysis.csharp/5.9.0 branch from ea3955a to 9082b02 Compare August 24, 2026 14:17
@dnyw4l3n13 dnyw4l3n13 self-assigned this Aug 24, 2026
… generator test projects

Bumping Microsoft.CodeAnalysis.CSharp to 5.9.0 in the source generator
projects surfaced a CS0433/CS1705 assembly version conflict in
Credfeto.Database.Source.Generation.Tests and
Credfeto.Database.Migrations.Source.Generation.Tests: both directly
ProjectReference their source generator, and an analyzer package still
resolves Microsoft.CodeAnalysis.CSharp 5.6.0 as the primary reference.
Apply the documented RemoveGeneratorNuGetCompileDependencies target and
pin an explicit 5.9.0 PackageReference, matching the pattern already
used in Credfeto.Database.Source.Generation.Benchmark.Tests.csproj.
@dnyw4l3n13

Copy link
Copy Markdown
Collaborator Author

Fixed in ca3ea46 - resolved the Microsoft.CodeAnalysis.CSharp 5.6.0/5.9.0 assembly version conflict (CS0433/CS1705) in the two source-generator test projects that broke build-pre-release, by applying the documented RemoveGeneratorNuGetCompileDependencies target and an explicit 5.9.0 override (same pattern already used in the Benchmark.Tests project). Full local build and test suite (392 tests) pass. Board moved to Development.

…target

The target was duplicated verbatim across three test .csproj files (two
added by the 5.9.0 version-conflict fix, one pre-existing in
Benchmark.Tests). All three already import the shared UnitTests.props,
so move the target there once and delete the per-project copies. Also
corrects a stale version number left in the Benchmark.Tests override
comment by the same version bump.
@dnyw4l3n13

Copy link
Copy Markdown
Collaborator Author

Simplify: applied cleanups - centralized the duplicated RemoveGeneratorNuGetCompileDependencies MSBuild target (was copy-pasted across three test .csproj files, including one pre-existing copy) into the shared UnitTests.props, and fixed a stale version number in a comment. Fixed in a6612eb.

…sproj files

Puts ProjectReference back before PackageReference, matching every other
test project in the repo; the prior commit incidentally reordered these
two while adding the Microsoft.CodeAnalysis.CSharp override.
@dnyw4l3n13

Copy link
Copy Markdown
Collaborator Author

Simplify: applied cleanups - restored conventional ItemGroup ordering (ProjectReference before PackageReference) in the two test csproj files, which had been incidentally reordered while adding the Microsoft.CodeAnalysis.CSharp override. Fixed in 9d31e67.

@dnyw4l3n13

Copy link
Copy Markdown
Collaborator Author

Simplify clean - advancing to code review

@dnyw4l3n13

Copy link
Copy Markdown
Collaborator Author

Code review clean - advancing to security review

@dnyw4l3n13

Copy link
Copy Markdown
Collaborator Author

Security review clean, advancing to coverage check

@dnyw4l3n13

Copy link
Copy Markdown
Collaborator Author

Non-code change - coverage ratchet skipped

@dnyw4l3n13
dnyw4l3n13 marked this pull request as ready for review August 24, 2026 23:37
@dnyw4l3n13
dnyw4l3n13 enabled auto-merge August 24, 2026 23:37
@dnyw4l3n13

Copy link
Copy Markdown
Collaborator Author

PR is ready: marked ready for review and auto-merge enabled.

@credfeto

Copy link
Copy Markdown
Owner

Super-linter summary

Language Validation result

All files and directories linted successfully

For more information, see the GitHub Actions workflow run

Powered by Super-linter

@dnyw4l3n13
dnyw4l3n13 merged commit a33149f into main Aug 26, 2026
42 checks passed
@dnyw4l3n13
dnyw4l3n13 deleted the depends/update-microsoft.codeanalysis.csharp/5.9.0 branch August 26, 2026 09:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-pr Pull request created automatically

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants