Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .config/dotnet-tools.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,14 +3,14 @@
"isRoot": true,
"tools": {
"dotnet-stryker": {
"version": "4.14.2",
"version": "5.0.0",
"commands": [
"dotnet-stryker"
],
"rollForward": false
},
"docfx": {
"version": "2.78.5",
"version": "2.81.0",
"commands": [
"docfx"
],
Expand Down
40 changes: 35 additions & 5 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,19 +1,49 @@
# Automated dependency update PRs. Complements .github/workflows/dependency-audit.yml
# (the scheduled vulnerability scan): Dependabot proposes upgrades, the audit fails loudly
# when a currently-referenced package acquires a known advisory.
#
# Updates are GROUPED so a normal month produces a couple of PRs, not one per package:
# every bump still lands as an exact pinned version and still has to pass the full CI
# matrix, but related bumps are reviewed (and fixed up, when a major breaks the build) together.
# Security updates are not delayed by the schedule — Dependabot raises them as soon as an
# advisory is published, in their own group.
version: 2
updates:
- package-ecosystem: nuget
directory: /
schedule:
interval: weekly
# One PR per dependency; the repo pins exact versions, so every bump is reviewed.
open-pull-requests-limit: 10
interval: monthly
open-pull-requests-limit: 5
groups:
# SourceLink and the test/benchmark stack: minor and patch bumps travel together.
nuget-minor-and-patch:
applies-to: version-updates
update-types:
- minor
- patch
# Majors get their own grouped PR: they are the ones that can need code changes.
nuget-major:
applies-to: version-updates
update-types:
- major
nuget-security:
applies-to: security-updates
patterns:
- "*"
ignore:
# 9.x moved from MIT to the Open Source Maintenance Fee EULA; 8.x is the last
# MIT-licensed line. Test-only dependency, pinned there on purpose.
- dependency-name: JsonSchema.Net
versions: [">= 9.0.0"]

# Keeps the SHA-pinned actions current: Dependabot updates the pinned commit and the
# human-readable version comment together, which is the only sane way to maintain
# SHA pinning by hand-edited workflows.
# SHA pinning by hand-edited workflows. All action bumps arrive as one PR.
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
interval: monthly
groups:
github-actions:
patterns:
- "*"
4 changes: 2 additions & 2 deletions .github/workflows/aot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,10 +26,10 @@ jobs:
binary: LogicalOptimizer.AotSmoke.exe

steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Setup .NET
uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
dotnet-version: 10.0.x

Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,10 +18,10 @@ jobs:
os: [ubuntu-latest, windows-latest]

steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Setup .NET
uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
dotnet-version: 10.0.x

Expand Down Expand Up @@ -63,7 +63,7 @@ jobs:

- name: Upload test results
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: test-results-${{ matrix.os }}
path: TestResults/**
Expand Down Expand Up @@ -119,7 +119,7 @@ jobs:

- name: Upload package contract report
if: always() && runner.os == 'Linux'
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: package-contract-report
path: package-contract-report.json
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/comparison.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,10 +16,10 @@ jobs:
timeout-minutes: 20

steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Setup .NET
uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
dotnet-version: 10.0.x

Expand Down Expand Up @@ -56,7 +56,7 @@ jobs:

- name: Upload comparison artifacts
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: cross-library-comparison
path: |
Expand All @@ -82,7 +82,7 @@ jobs:
timeout-minutes: 90

steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

# Keep what is committed, so the fresh run can be diffed against it for determinism.
- name: Set aside the committed results
Expand Down Expand Up @@ -112,7 +112,7 @@ jobs:

- name: Upload the reproduced report
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: comparison-reproduced-from-scratch
path: |
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/dependency-audit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,10 +18,10 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Setup .NET
uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
dotnet-version: 10.0.x

Expand All @@ -43,7 +43,7 @@ jobs:

- name: Upload audit log
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: dependency-audit
path: audit.txt
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -44,10 +44,10 @@ jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Setup .NET
uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
dotnet-version: 10.0.x

Expand Down Expand Up @@ -75,7 +75,7 @@ jobs:
run: dotnet docfx docs-site/docfx.json

- name: Upload Pages artifact
uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3.0.1
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
with:
path: docs-site/_site

Expand All @@ -88,4 +88,4 @@ jobs:
steps:
- name: Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4.0.5
uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1
6 changes: 3 additions & 3 deletions .github/workflows/exhaustive.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,10 +25,10 @@ jobs:
timeout-minutes: 120

steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Setup .NET
uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
dotnet-version: 10.0.x

Expand All @@ -48,7 +48,7 @@ jobs:

- name: Upload results
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: exhaustive-results
path: TestResults/**
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/perf.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,10 +27,10 @@ jobs:
timeout-minutes: 40

steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Setup .NET
uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
dotnet-version: 10.0.x

Expand Down Expand Up @@ -67,7 +67,7 @@ jobs:

- name: Upload BenchmarkDotNet artifacts
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: perf-benchmarkdotnet
path: |
Expand Down
14 changes: 7 additions & 7 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,10 +27,10 @@ jobs:
contents: write # checkout + attach the evidence bundle to this tag's release
attestations: write # build provenance attestations for the published packages
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Setup .NET
uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
dotnet-version: 10.0.x

Expand Down Expand Up @@ -94,7 +94,7 @@ jobs:
# the bundle is never built — upload them directly so a refused release is diagnosable.
- name: Upload test results
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: release-test-results
path: TestResults/**
Expand Down Expand Up @@ -170,7 +170,7 @@ jobs:
# for real (including the Linux Native AOT smoke of the packed bytes), nothing below does.
- name: Upload pre-publish evidence (dry run)
if: env.PUBLISH != 'true'
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: dry-run-evidence-${{ env.VERSION }}
path: |
Expand All @@ -183,13 +183,13 @@ jobs:
# and a dry run releases nothing.
- name: Attest build provenance
if: env.PUBLISH == 'true'
uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2.4.0
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-path: 'artifacts/*.nupkg'

- name: Upload packages as run artifacts
if: env.PUBLISH == 'true'
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: nupkg-${{ env.VERSION }}
path: |
Expand Down Expand Up @@ -242,7 +242,7 @@ jobs:

- name: Upload evidence bundle as a run artifact
if: env.PUBLISH == 'true'
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: release-evidence-${{ env.VERSION }}
path: evidence/**
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/sat-benchmarks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,10 +20,10 @@ jobs:
timeout-minutes: 30

steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Setup .NET
uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4.3.1
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
dotnet-version: 10.0.x

Expand All @@ -45,7 +45,7 @@ jobs:

- name: Upload test results
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: sat-corpus-trx
path: '**/TestResults/*.trx'
Expand All @@ -60,7 +60,7 @@ jobs:

- name: Upload BenchmarkDotNet artifacts
if: ${{ github.event_name == 'workflow_dispatch' && inputs.run_benchmarkdotnet }}
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: sat-benchmarkdotnet
path: BenchmarkDotNet.Artifacts/**
Expand Down
15 changes: 14 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,20 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

### Fixed
## [4.0.1] - 2026-09-25

### Changed

- **Dependencies brought current.** SourceLink 10.0.401 (build-only, `PrivateAssets="All"`), and
in the non-shipping projects CsCheck 4.9.1, Microsoft.NET.Test.Sdk 18.10.1,
xunit.runner.visualstudio 4.0.0, TngTech.ArchUnitNET.xUnit 0.13.4, BenchmarkDotNet 0.15.8;
tool manifest docfx 2.81.0 and dotnet-stryker 5.0.0; workflow actions checkout v7.0.1,
setup-dotnet v6.0.0, upload-artifact v7.0.1, upload-pages-artifact v5.0.0, deploy-pages v5.0.1
and attest-build-provenance v4.2.2 (still SHA-pinned). JsonSchema.Net moves to 8.0.5, the last
MIT-licensed line: 9.x ships under the Open Source Maintenance Fee EULA, so Dependabot ignores
it. The library's own dependency graph is unchanged.
- **Dependabot groups its PRs.** Monthly, with minor/patch bumps, majors, security fixes and
GitHub Actions each arriving as one grouped PR instead of one PR per package.

- **The release workflow no longer finishes green without a GitHub release.** Its last step
attached the evidence bundle and the attested `.nupkg`/`.snupkg`/`SHA256SUMS.txt` only when a
Expand Down
2 changes: 1 addition & 1 deletion Directory.Build.props
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
TreatWarningsAsErrors.
-->
<PropertyGroup>
<Version>4.0.0</Version>
<Version>4.0.1</Version>
<Authors>Oleksandr Panasenko</Authors>
<PackageLicenseExpression>Apache-2.0</PackageLicenseExpression>
<PackageProjectUrl>https://AlexanderV.github.io/LogicalOptimizer/</PackageProjectUrl>
Expand Down
2 changes: 1 addition & 1 deletion LogicalOptimizer.Bdd/LogicalOptimizer.Bdd.csproj
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@
</ItemGroup>

<ItemGroup>
<PackageReference Include="Microsoft.SourceLink.GitHub" Version="8.0.0" PrivateAssets="All" />
<PackageReference Include="Microsoft.SourceLink.GitHub" Version="10.0.401" PrivateAssets="All" />
<ProjectReference Include="..\LogicalOptimizer.Core\LogicalOptimizer.Core.csproj" />
</ItemGroup>

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
</PropertyGroup>

<ItemGroup>
<PackageReference Include="BenchmarkDotNet" Version="0.14.0" />
<PackageReference Include="BenchmarkDotNet" Version="0.15.8" />
</ItemGroup>

<ItemGroup>
Expand Down
2 changes: 1 addition & 1 deletion LogicalOptimizer.Core/LogicalOptimizer.Core.csproj
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@
</ItemGroup>

<ItemGroup>
<PackageReference Include="Microsoft.SourceLink.GitHub" Version="8.0.0" PrivateAssets="All" />
<PackageReference Include="Microsoft.SourceLink.GitHub" Version="10.0.401" PrivateAssets="All" />
</ItemGroup>

</Project>
Loading
Loading