.Net: Bump Aspire.Hosting.AppHost from 13.4.6 to 13.5.3 - #14395
.Net: Bump Aspire.Hosting.AppHost from 13.4.6 to 13.5.3#14395dependabot[bot] wants to merge 1 commit into
Conversation
--- updated-dependencies: - dependency-name: Aspire.Hosting.AppHost dependency-version: 13.5.3 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
🟡 Changes recommended
The Aspire package versions are now mixed across minor versions in central management, which is likely to cause dependency/compatibility issues and should be aligned.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Updates the centrally managed .NET package versions to consume a newer Aspire AppHost release, which affects the repo’s Aspire-based AppHost demo projects that rely on Directory.Packages.props for package version pinning.
Changes:
- Bumped
Aspire.Hosting.AppHostfrom13.4.6to13.5.3in central package management.
File summaries
| File | Description |
|---|---|
dotnet/Directory.Packages.props |
Updates the centrally pinned Aspire AppHost package version used by the .NET sample AppHost projects. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| <PackageVersion Include="Aspire.Azure.AI.OpenAI" Version="9.3.1-preview.1.25305.6" /> | ||
| <PackageVersion Include="Aspire.Azure.Search.Documents" Version="13.4.6" /> | ||
| <PackageVersion Include="Aspire.Hosting.AppHost" Version="13.4.6" /> | ||
| <PackageVersion Include="Aspire.Hosting.AppHost" Version="13.5.3" /> |
There was a problem hiding this comment.
MAF Automated Review — Iteration 1
Result: Findings reported
Scope: full PR (1 commit(s)): b414722db52b
Model: gpt-5.6-sol-fast
Overview
The PR centrally updates Aspire.Hosting.AppHost for three sample AppHost projects, and central package management keeps the dependency selection explicit. The warning-as-error solution build provides a strong compatibility guard, but 13.5.3 introduces a default ASPIRE010 warning that this guard promotes to an error for the included ChatWithAgent AppHost. The package bump therefore cannot pass the required .NET build until the new CLI-bundle choice is configured explicitly.
Reviewed the supplied pull-request change set across correctness, security/reliability, architecture, and failure behavior.
1 verified finding remained after source verification (1 high) across 1 file. Details are attached to the affected lines below.
Affected areas: dotnet/Directory.Packages.props
| <PackageVersion Include="Aspire.Azure.AI.OpenAI" Version="9.3.1-preview.1.25305.6" /> | ||
| <PackageVersion Include="Aspire.Azure.Search.Documents" Version="13.4.6" /> | ||
| <PackageVersion Include="Aspire.Hosting.AppHost" Version="13.4.6" /> | ||
| <PackageVersion Include="Aspire.Hosting.AppHost" Version="13.5.3" /> |
There was a problem hiding this comment.
The 13.5.3 package now emits ASPIRE010 when AspireUseCliBundle is unset, because its props default that property to false. ChatWithAgent.AppHost is included in SK-dotnet.slnx, and CI builds every solution with --warnaserror, so this upgrade makes the required .NET build fail before tests run. Please explicitly enable AspireUseCliBundle for the AppHost projects, or suppress ASPIRE010 where retaining the legacy behavior is intentional.
Updated Aspire.Hosting.AppHost from 13.4.6 to 13.5.3.
Release notes
Sourced from Aspire.Hosting.AppHost's releases.
13.5.3
What's New in Aspire 13.5.3
Patch release for Aspire 13.5 that fixes Dashboard Graph view crashes for resources with multi-path icons and restores missing public URLs for DevTunnel resources.
🐛 Fixes
📊 Dashboard Graph view could crash for Azure Blob resources — Resources such as those created with
AddBlobsuse icons containing multiple SVG paths, which caused an XML parsing exception and broke the dashboard circuit. The graph now combines multi-path icons correctly. Regression introduced in 13.5. Fixes #19489. (#19585, backport of #19579,@sebastienros)🌐 DevTunnel public URLs were missing from the Dashboard and MCP snapshots — DevTunnel port resources could report
RunningandHealthywhile showing no public URLs. Proxyless port allocation is now limited to compute and container resources, allowing DevTunnels to publish their actual public endpoints. Regression introduced in 13.5. Fixes #19496. (#19625, backport of #19590,@karolz-ms,@danegsta)🏷️ Housekeeping
Full Changelog: v13.5.2...v13.5.3
Full commit: b5f143315ffb6968ea939a9978797a5b20e4c688
13.5.2
What's New in Aspire 13.5.2
Patch release for Aspire 13.5 that removes an unused native helper binary from the Windows CLI archives so 13.5 servicing releases stay publishable to WinGet.
🐛 Fixes
hex1bpty.exe— The Windows CLI archives (aspire-cli-win-{x64,arm64}-*.zip) bundled Hex1b's out-of-process PTY host, which Aspire never executes (DCP owns every pseudo-terminal Aspire surfaces). Besides the wasted download, the extra unexplained executable stalled the WinGet publish, since every binary in the archive goes through executable and malware validation. A build-only MSBuild target now drops the file from the CLI publish output; Unix native assets are unaffected. Regression new in 13.5. ([#19557]([release/13.5] Exclude unused hex1bpty.exe from published CLI archives aspire#19557), backport of #19554,@mitchdenny)🏷️ Housekeeping
Full Changelog: [v13.5.1...v13.5.2](microsoft/aspire@v13.5.1...v13.5.2)
Full commit: [a22cec24d76e764b3681977e314ab4a0aeed0240](microsoft/aspire@a22cec2)
13.5.1
What's New in Aspire 13.5.1
Patch release for Aspire 13.5 fixing a TypeScript/Java polyglot AppHost compatibility regression when running the 13.5 SDK under an older (13.4.x) CLI, plus a DCP update and release-pipeline housekeeping.
🐛 Fixes
🍎 Polyglot AppHosts could crash on startup on macOS — On macOS, polyglot (TypeScript/Python/Java/Go/Rust) AppHosts could crash during startup due to an interaction between how DCP's Go runtime forks detached processes and how .NET Native AOT installs its signal handlers. Updated DCP (Developer Control Plane) to 0.25.13 to resolve the crash. ([#19528]([release/13.5] [main] Update dependencies from microsoft/dcp aspire#19528))
🔗 Polyglot AppHosts on the 13.5 SDK crashed under an older CLI with
MissingMethodException— A TypeScript or Java AppHost built with the 13.5 SDK failed to start when launched by an older (13.4.x) CLI, because the newer codegen calledAspire.TypeSystemmembers that don't exist in the CLI's older contract. Code generation now probes for these additive capabilities before using them, so older CLIs skip only the unsupported feature and startup succeeds. Regression introduced in 13.5 by #19365. Fixes #19503. ([#19524]([release/13.5] Preserve TypeSystem compatibility with older CLIs aspire#19524), backport of #19506,@adamint)🏷️ Housekeeping
📦 Updated DCP (Developer Control Plane) to 0.25.13 ([#19528]([release/13.5] [main] Update dependencies from microsoft/dcp aspire#19528))
🔧 Restored WinGet publication using .NET 9
wingetcreate([#19509]([release/13.5] fix(release): Restore WinGet publication with .NET 9 wingetcreate aspire#19509))🧹 Removed the pipeline-scoped
Publish-Build-Assetsgroup from the release pipeline ([#19523]([release/13.5] Remove pipeline-scoped Publish-Build-Assets group aspire#19523), [#19163](Remove Publish-Build-Assets variable group from release/13.5 aspire#19163))🚀 Bumped branding to 13.5.1 ([#19531](Increment patch version from 0 to 1 aspire#19531))
Full Changelog: [v13.5.0...v13.5.1](microsoft/aspire@v13.5.0...v13.5.1)
Full commit: [69db530a4816698cf1d5fa4557933e0ac4f127c6](microsoft/aspire@69db530)
13.5.0
Aspire 13.5.0
Aspire 13.5 is a developer-experience release focused on a richer, more interactive AppHost, closer C# and TypeScript parity, sharper tooling, more flexible deployment modeling, and a broad set of runtime-stability improvements.
Highlights
WithTerminal()API lets resources host REPLs, shells, TUIs, and other interactive programs directly in the dashboard, with an opt-inaspire terminalCLI command for attaching from your shell.ASPIREATS001experimental diagnostic and gain custom health checks, container file copying, HTTPS developer certificates, faster startup, and several reliability fixes that further close the gap with C#.aspire stop --force,aspire update --migrate,aspire doctor, docs search, signal handling, and stale-socket cleanup all improve day-to-day workflows.Aspire.Hosting.Dotnetpackage models .NET projects by path; Radius deployment arrives in preview; and Foundry Local, Redis modules, dev tunnels, Go debugging, and other integrations gain new capabilities.Notable changes include hosting context
ServiceProviderproperties being renamed toServices,PublishAsConnectionStringbecoming obsolete in favor ofAddConnectionString, removal ofaspire ps --resourcesand--include-hiddenin favor ofaspire describe, earlier proxyless endpoint port allocation, deprecation of the GitHub Models integration, removal of the dashboard AI Assistant, and opt-in rather than automatic dashboard launch from the VS Code extension.See the full list and migration guidance in the Aspire 13.5 breaking changes.
📖 Learn more
For complete details, examples, migration guidance, and everything new in this release, read What's new in Aspire 13.5.
Thank you to all the community contributors who helped make Aspire 13.5 possible! 💜
Full Changelog: v13.4.6...v13.5.0
Full commit: e076d8e427cb3afb528dbd605acd74c3aea69f94
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)