Skip to content

fix: update dependencies and support YamlDotNet 18 - #67

Merged
yongchul merged 1 commit into
mainfrom
fix/dependency-updates
Oct 2, 2026
Merged

yongchul merged 1 commit into
mainfrom
fix/dependency-updates

Conversation

@yongchul

@yongchul yongchul commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Thank you for submitting a pull request to the Substrait project. Please keep
your description clear and concise for reviewers.

Change Summary [REQUIRED]

Update the remaining NuGet dependencies and SBOM tool, adapt extension loading
to YamlDotNet 18, and align package dependency validation.

Motivation [REQUIRED]

Supersedes the overlapping dependency updates in #53 and #57.

The TUnit migration removed the obsolete MSTest dependencies, but the grouped
updates also require a YamlDotNet interface adaptation and matching package
dependency expectations. This applies the seven remaining updates on current
main without reintroducing MSTest.

Reviewer Context [OPTIONAL]

  • Forward YamlDotNet's root deserializer through the existing collection adapter.
    Regression tests cover nested lists and dictionaries, polymorphic arguments,
    aliases, and invalid YAML.
  • Keep explicit package dependency checks rather than weakening validation to
    accept arbitrary version changes.
  • Leave the generated Substrait specification packages at 0.104.0.

Validation [REQUIRED]

  • dotnet format Substrait.sln --verify-no-changes --no-restore - passed.
  • dotnet build Substrait.sln --configuration Release --no-restore - passed with no warnings.
  • dotnet test --solution Substrait.sln --configuration Release --no-build - passed: 3,838 cases, no skips.
Additional package and compatibility validation

Each command below passed:

dotnet run --project tools/Substrait.MetadataGenerator --configuration Release --no-restore -- --check
dotnet pack src/Substrait/Substrait.csproj --configuration Release --no-build --output artifacts/packages -p:PackageVersion=0.1.0-preview.dependency-fixes.1
pwsh -NoProfile -File eng/Validate-Package.ps1 -PackagePath artifacts/packages/Substrait.Net.0.1.0-preview.dependency-fixes.1.nupkg -SymbolsPackagePath artifacts/packages/Substrait.Net.0.1.0-preview.dependency-fixes.1.snupkg -ExpectedVersion 0.1.0-preview.dependency-fixes.1
dotnet tool restore
dotnet tool run sbom-tool generate -b artifacts/packages -bc src/Substrait -pn Substrait.Net -pv 0.1.0-preview.dependency-fixes.1 -ps 'Organization: Substrait' -nsb https://github.com/substrait-io/substrait-csharp -mi SPDX:2.2
dotnet tool run sbom-tool validate -b artifacts/packages -o artifacts/sbom-validation.json -mi SPDX:2.2
dotnet run --project tests/PackageSmokeTest/PackageSmokeTest.csproj --configuration Release --no-restore -p:SmokeTestPackageVersion=0.1.0-preview.dependency-fixes.1 -p:SmokeTestTargetFramework=net8.0
dotnet run --project tests/PackageSmokeTest/PackageSmokeTest.csproj --configuration Release --no-restore -p:SmokeTestPackageVersion=0.1.0-preview.dependency-fixes.1 -p:SmokeTestTargetFramework=net9.0
dotnet run --project tests/PackageSmokeTest/PackageSmokeTest.csproj --configuration Release --no-restore -p:SmokeTestPackageVersion=0.1.0-preview.dependency-fixes.1 -p:SmokeTestTargetFramework=net10.0
dotnet build tests/PackageSmokeTest/PackageSmokeTest.csproj --configuration Release --no-restore -p:SmokeTestPackageVersion=0.1.0-preview.dependency-fixes.1 -p:SmokeTestTargetFramework=net462

The initial consumer restore using the checked-in NuGet.org configuration failed
with NU1900 because its vulnerability-data endpoint was unreachable locally.
Consumer restores and runs subsequently passed using the configured package feed
plus the local preview package source, without disabling auditing.

.NET Framework 4.6.2 was cross-compiled only; runtime execution was not performed
on macOS and remains a Windows CI check.

Public API and compatibility [REQUIRED]

No Substrait public API or wire-format changes. Runtime dependency minimums
increase, including Google.Protobuf 3.36.2 and YamlDotNet 18.1.0. The existing
net10.0, net8.0, and netstandard2.0 library targets are retained.

Breaking changes [REQUIRED]

None to the Substrait API or specification. Consumers must permit the updated
dependency versions.

Summary by CodeRabbit

  • Bug Fixes
    • Improved loading of nested YAML definitions, including arguments, aliases, and metadata. Invalid or malformed YAML continues to be rejected with clear errors.
  • Documentation
    • Updated package compatibility information to reflect the current minimum runtime dependency versions.

Apply the remaining NuGet and SBOM tool updates after the TUnit migration. Forward the root deserializer required by YamlDotNet, cover nested collections and aliases, and align package dependency validation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: d309ce3c-e16c-4f08-b709-738167421590
📥 Commits

Reviewing files that changed from the base of the PR and between d57d09a and ab2d850.

📒 Files selected for processing (6)
  • .config/dotnet-tools.json
  • Directory.Packages.props
  • docs/preview-package.md
  • eng/Validate-Package.ps1
  • src/Substrait/Tools/ExtensionUtils.cs
  • tests/Substrait.Tests/Tools/ExtensionUtilsTests.cs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Central package versions and package validation expectations were updated. The YAML collection adapter now forwards the root deserializer, with tests for nested YAML and invalid input. Compatibility documentation and the configured SBOM tool version were also updated.

Changes

YAML compatibility and package versions

Layer / File(s) Summary
Dependency versions and YAML adapter
Directory.Packages.props, src/Substrait/Tools/ExtensionUtils.cs, tests/Substrait.Tests/Tools/ExtensionUtilsTests.cs, eng/Validate-Package.ps1, docs/preview-package.md
Package versions and validation expectations were updated. The YAML adapter forwards the root deserializer to its inner deserializer for other types. Tests cover nested scalar-function YAML and invalid YAML. Compatibility documentation records the dependency minimums and adapter behavior.

SBOM tool version

Layer / File(s) Summary
Update SBOM tool version
.config/dotnet-tools.json
The configured microsoft.sbom.dotnettool version changed from 4.1.5 to 4.1.13.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to ab2d8

This change updates dependencies and adapts YAML loading to the new YamlDotNet version, with tests added for the affected behavior. No merge-blocking issue was found. Consumers must allow the higher dependency minimums.

Security Architecture Review

Security architecture risk: 🔵 Low · up to ab2d8

The reviewed change preserves the loader’s explicit type mappings, namespace handling, and collection conversions. No expanded access or weakened control was identified, but the upgraded deserializer’s security-sensitive callback behavior remains unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The directly supported exposure is YAML parsing within a consuming process that invokes Load. Untrusted extension content could reach this path through caller-supplied streams or resolvers, but network reachability, tenant isolation, and deployment privileges are not established by this evidence.

Trust Boundaries and Controls

  • observed — Caller-provided stream resolution, explicit polymorphic mappings, and namespace selection remain unchanged across the reviewed modification. The new callback is passed to the existing inner deserializer; this establishes the local delegation path, not equivalence of YamlDotNet 18 object construction or alias semantics.

Resilience and Maintainability Implications

  • observed — The stream loader constructs the collection only after deserialization and namespace validation, and its reader is disposed through a using declaration on success or failure. The callback change does not modify this local cleanup and return ordering.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 2 files. (4 skipped: 4 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the primary changes: dependency updates and YamlDotNet 18 support.
Description check ✅ Passed The description includes all required sections, explains the motivation, records validation results, and documents compatibility and breaking-change impact.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 2 files. (4 skipped: 4 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yongchul
yongchul marked this pull request as ready for review October 2, 2026 23:48
@yongchul
yongchul merged commit 3058e9b into main Oct 2, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant