.Net: Bump Aspire.Hosting.Azure.CognitiveServices from 13.0.0 to 13.3.0#13996
.Net: Bump Aspire.Hosting.Azure.CognitiveServices from 13.0.0 to 13.3.0#13996dependabot[bot] wants to merge 1 commit into
Conversation
--- updated-dependencies: - dependency-name: Aspire.Hosting.Azure.CognitiveServices dependency-version: 13.3.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Automated Code Review
Reviewers: 4 | Confidence: 89%
✓ Correctness
This is a straightforward minor version bump of Aspire.Hosting.Azure.CognitiveServices from 13.0.0 to 13.3.0. While this creates a version skew with other Aspire packages in the same file (Aspire.Hosting.AppHost and Aspire.Hosting.Azure.Search remain at 13.0.0), this is safe — NuGet's dependency resolution will pick the highest compatible version for shared transitive dependencies, and Aspire extension packages within the same major version are designed to be independently upgradable. No correctness issues found.
✓ Security Reliability
This is a straightforward minor version bump of Aspire.Hosting.Azure.CognitiveServices from 13.0.0 to 13.3.0 in the central package management file. The release notes indicate the update includes a security patch (CVE-2026-40894 in OpenTelemetry dependencies via 13.2.4) along with feature additions and bug fixes. No security or reliability concerns with this change.
✓ Test Coverage
This is a straightforward minor version bump of the Aspire.Hosting.Azure.CognitiveServices package from 13.0.0 to 13.3.0 in the central package management file. The package is only consumed by two sample/demo Aspire AppHost projects (ChatWithAgent.AppHost and ProcessFramework.Aspire.SignalR.AppHost), which are infrastructure orchestration projects without associated unit tests. No behavioral code in this repository is changed, so there is no new or modified behavior requiring test coverage.
✗ Design Approach
The dependency bump introduces version skew inside the repo’s Aspire AppHost stack without updating the corresponding AppHost package or SDK pins. The current codebase consistently keeps those hosting components on the same Aspire release, and both AppHost samples consume
Aspire.Hosting.AppHostandAspire.Hosting.Azure.CognitiveServicestogether, so bumping only one of them is a risky design change rather than a self-contained package refresh.
Flagged Issues
- This changes
Aspire.Hosting.Azure.CognitiveServicesto 13.3.0 while the same AppHost projects still pinAspire.Hosting.AppHostandAspire.AppHost.Sdkto 13.0.0. The repo's existing pattern is to keep the Aspire hosting stack aligned, so this PR should either update the matching AppHost pins too or leave this package on 13.0.0.
Automated review by dependabot[bot]'s agents
| <PackageVersion Include="Aspire.Azure.Search.Documents" Version="9.5.1" /> | ||
| <PackageVersion Include="Aspire.Hosting.AppHost" Version="13.0.0" /> | ||
| <PackageVersion Include="Aspire.Hosting.Azure.CognitiveServices" Version="13.0.0" /> | ||
| <PackageVersion Include="Aspire.Hosting.Azure.CognitiveServices" Version="13.3.0" /> |
There was a problem hiding this comment.
This single-package bump creates a mixed Aspire hosting stack in the sample AppHosts: they still reference Aspire.Hosting.AppHost and Aspire.AppHost.Sdk at 13.0. The existing repo pattern is to keep these Aspire hosting components aligned, so please update the matching AppHost pins in the same change or keep this package at 13.0.0.
Updated Aspire.Hosting.Azure.CognitiveServices from 13.0.0 to 13.3.0.
Release notes
Sourced from Aspire.Hosting.Azure.CognitiveServices's releases.
13.3.0
Aspire 13.3.0
Aspire 13.3 is here! 🚀 This release is packed with new ways to deploy, debug, and build distributed apps — including
aspire destroy, browser telemetry in the dashboard, Kubernetes deployment, first-class JavaScript publishing, and major TypeScript AppHost parityimprovements.
Highlights
aspire destroytears down Azure, Kubernetes, and Docker Compose deployments, and pipeline summaries make deploy/publish/destroy runs easier to follow.aspire deploycan now generate Helm-based Kubernetes deployments, with first-class Ingress and Gateway API routing.PublishAs*methods support static sites, Node servers, npm-script apps, Next.js, Vite, Bun, Yarn, and pnpm.withEnvironment, Docker Compose hooks, endpoint expressions, Azure Container Apps domains, and more close the gap with C# AppHosts.aspire dashboard run, install the CLI as a NativeAOTdotnet tool, and search API docs from the terminal.Notable breaking changes include
--log-levelbecoming--pipeline-log-level, the dashboard MCP server being replaced byaspire agent init,dotnet new aspire-py-startermoving toaspire new aspire-py-starter, and several API shape updates across AKS,Foundry, JavaScript diagnostics, and TypeScript AppHost helpers.
See the full list in the Aspire 13.3 breaking changes.
📖 Learn more
For the full details, examples, migration guidance, and everything new in this release, check out What's new in Aspire 13.3.
Thank you to all the community contributors who helped make Aspire 13.3 possible! 💜
13.2.4
Aspire 13.2.4
What's New in Aspire 13.2.4
Patch release addressing a security advisory in OpenTelemetry dependencies.
🐛 Fixes
🏷️ Housekeeping
13.2.4 (#16436)
13.2.3
What's New in Aspire 13.2.3
Patch release focused on CLI packaging, signing, and reliability fixes.
🐛 Fixes
🔧 Improvements
🏷️ Housekeeping
13.2.2
This is a servicing release focused on bug fixes and platform improvements.
🐛 Bug Fixes
13.2 regressions impacting IDE-based execution (#15714)
🔒 Security & Certificates
🏗️ Infrastructure & Platform
0.22.11 (#15713)
💻 CLI Improvements
13.2.1
🐛 Bug Fixes
✨ Improvements
13.2.0
Aspire 13.2
Aspire 13.2 brings major CLI enhancements, a new TypeScript AppHost (preview), dashboard data export/import, Microsoft Foundry integration, and multi-language improvements — all focused on making local development more streamlined for developers and AI coding agents
alike.
Highlights
and aspire agent (renamed from aspire mcp) for AI agent integration.
Notable breaking changes include service discovery env vars now using endpoint scheme instead of name, aspire.config.json replacing split config files, AIFoundry → Foundry rename, WithSecretBuildArg → WithBuildSecret, and updated default Azure credential behavior.
See the full list of breaking changes.
📖 Learn more
For the full details on everything in this release, check out the What's new in Aspire 13.2 documentation.
Thank you to all the community contributors who helped make this release happen! 💜
13.1.3
What's Changed
Full Changelog: microsoft/aspire@v13.1.2...v13.1.3
13.1.2
What's Changed
Full Changelog: microsoft/aspire@v13.1.1...v13.1.2
13.1.1
What's Changed
Full Changelog: microsoft/aspire@v13.1.0...v13.1.1
13.1.0
We are excited to share that our 13.1.0 release of Aspire has shipped! All of the packages are available in NuGet.org now. Head over to https://aspire.dev/whats-new/aspire-13-1/ to find what's new in 13.1.0!
What's Changed
ExcludeFromMcp()resource extension by @JamesNK in AddExcludeFromMcp()resource extension aspire#12515aspire updatecommand by @Copilot in Add CLI self-update prompts toaspire updatecommand aspire#12395CertificateAuthorityCollectionResourceby @danegsta in Add missing namespace toCertificateAuthorityCollectionResourceaspire#12639... (truncated)
13.0.2
This patch is updating our Project Templates for our Python starter app to ensure we depend on the latest version of React. This is out of an abundance of caution, as we don't depend on any of the react packages that were flagged as vulnerable in GHSA-fv66-9v8q-g76r.
What's Changed
Full Changelog: microsoft/aspire@v13.0.1...v13.0.2
13.0.1
What's Changed
Full Changelog: microsoft/aspire@v13.0.0...v13.0.1
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)