Skip to content

Update NuGet dependencies and fix issues from analyzer changes - #30

Merged
Malcolmnixon merged 1 commit into
mainfrom
chore/manual-dependency-update
Aug 10, 2026
Merged

Malcolmnixon merged 1 commit into
mainfrom
chore/manual-dependency-update

Conversation

@Malcolmnixon

Copy link
Copy Markdown
Member

This pull request primarily updates package dependencies across multiple projects to their latest versions, with a focus on build tools, analyzers, and test SDKs. Additionally, it addresses a false positive from the SonarAnalyzer (S8969) by suppressing related warnings in specific nullable flow scenarios, and includes a minor documentation clarification.

Dependency updates:

  • Updated Polyfill, Microsoft.SourceLink.GitHub, and DemaConsulting.ApiMark.MSBuild package references to newer versions in all main projects for improved compatibility and security. [1] [2] [3] [4] [5]
  • Upgraded SkiaSharp and native asset packages in DemaConsulting.Rendering.Skia to version 4.151.1 for enhanced rendering support.
  • Updated code analyzer packages: Microsoft.CodeAnalysis.NetAnalyzers to 10.0.302 and SonarAnalyzer.CSharp to 10.32.0.713 across all projects, including test projects, for better code analysis and static checking. [1] [2] [3] [4] [5] [6] [7] [8]
  • Upgraded Microsoft.NET.Test.Sdk to 18.8.1 in all test projects for improved test execution and compatibility. [1] [2] [3] [4]

Code quality and documentation improvements:

  • Suppressed SonarAnalyzer rule S8969 (false positive) with #pragma warning disable/restore S8969 in several files to avoid incorrect nullable warnings in complex pattern-matching scenarios. [1] [2] [3]
  • Clarified XML documentation in SkiaRasterRenderer.cs regarding SKColor.Parse(string).

Test and code consistency:

  • Minor test assertion simplification in MergeRegionGraphAssemblerTests.cs for clarity.

Manually applies the dependency bumps dependabot has been unable to land
(the 'Run Dependabot' step has been timing out at 55 minutes):
- Microsoft.CodeAnalysis.NetAnalyzers 10.0.301 -> 10.0.302
- Microsoft.SourceLink.GitHub 10.0.300 -> 10.0.301
- Polyfill 10.11.2 -> 11.0.2
- SonarAnalyzer.CSharp 10.29.0.143774 -> 10.32.0.713
- Microsoft.NET.Test.Sdk 18.7.0 -> 18.8.1
- SkiaSharp/SkiaSharp.NativeAssets.* (Rendering.Skia) 4.150.0 -> 4.151.1,
  keeping the Win32/Linux.NoDependencies/macOS native asset pins and the
  core SkiaSharp version in lockstep across all three platforms

Fixes required by these bumps:
- SkiaSharp 4.151.1 added an SKColor.Parse(ReadOnlySpan<char>) overload,
  making the existing <see cref="SKColor.Parse"/> doc comment ambiguous;
  disambiguated to SKColor.Parse(string).
- SonarAnalyzer.CSharp 10.32.0's new S8969 rule ("remove this redundant
  null-forgiving operator") is a false positive on switch pattern-match
  `when` clauses and on casts of MethodInfo.Invoke's object? result: the
  compiler's own nullable flow analysis (CS8602/CS8604/CS8605) still
  requires the operator in these exact spots. Suppressed with scoped
  #pragma warning disable/restore S8969, following this repo's existing
  suppression convention (see AxisTransform.cs). One occurrence (guarded
  by a preceding Assert.NotNull) was a genuine redundancy and was removed
  instead.

Verified: full solution builds with 0 warnings/errors and all tests pass
across net481/net8.0/net9.0/net10.0.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant