Repository navigation
Releases: xshaheen/headless-sdk
Release list
0.4.4
What's changed
Analyzers now do about half the work for the same findings, and a local build can skip them entirely. On headless-framework (434 projects, full rebuild), analyzer CPU time fell from 533 s to 275 s and a full build from 61 s to 46 s; with RunAnalyzersDuringBuild=false the build takes 29 s.
⚠ Breaking changes
- Asyncify is no longer an implicit analyzer reference. It cost 12% of analyzer time and was last updated in 2015. VSTHRD002 now reports synchronous task waits (
.Wait(),.Result,GetAwaiter().GetResult()) as a suggestion.AsyncifyInvocationandAsyncifyVariableentries in a consumer.editorconfigbecome inert. - Severity changes. About 100 rules that duplicated another rule are now
none, and twelve VSTHRD rules that only apply inside Visual Studio extensions are off. MA0045, CA1508, and VSTHRD003 are off. CA5359, CA2002, and MA0064 are errors, keeping the severity of the MA0039 and MT1000–MT1002 rules they replace. VSTHRD002 changes fromnonetosuggestion. - The
editorconfig.txtscaffold is editor-only. A newly scaffolded.editorconfigcarries editor, formatter, and ReSharper settings, and no analyzer severities, code-style preferences, or naming rules. A consumer.editorconfigoutranks the SDK, so a repository that copied an earlier scaffold keeps the old severities until it deletes the copied severity lines. - Crash and hang dumps are CI-only by default. Local
dotnet testno longer adds--crashdumpor--hangdump. SetEnableTestDumps=trueto restore them.
Features
- Local analyzer opt-out.
RunAnalyzersDuringBuild=falseorRunAnalyzersDuringLiveAnalysis=falseinDirectory.Build.propsnow takes effect for local builds. CI and AI-agent builds still run analyzers. Do not pass them as a global property (-p:orDirectory.Build.rsp), which would also override CI and agent builds. - One rule per defect. Where analyzer packages overlap, the SDK keeps the rule consumers already enforce and turns the duplicate off, so each defect is reported once. Blocking calls in async code report through CA1849; culture and comparison defaults report through MA0001, MA0074, and MA0011. Each
noneentry's comment names the rule that replaces it. - The injected analyzer configs are reorganized: one section per analyzer family, rules sorted by ID, a comment on every entry.
Fixes
- SARIF 2.1 compiler crash. With 0.4.3, a build writing a SARIF 2.1 error log could crash the compiler with
Unexpected value 'Default' of type 'Microsoft.CodeAnalysis.ReportDiagnostic'. The injected config no longer containsdotnet_analyzer_diagnostic.severity = default. - CA1510–CA1513 no longer contradict the guard-clause ban. While
BannedSymbols.GuardClauses.txtis active, these rules are off, because they recommend the helpers that list bans.
Full Changelog: 0.4.3...0.4.4
0.4.3
What's changed
Fixes
- The banned-symbol lists no longer report RS0030 in generated code. 0.4.2 reported it there too, so a project using a Microsoft source generator that emits the banned BCL guard helpers failed any build that treats warnings as errors. The configuration-binding generator (
EnableConfigurationBindingGenerator), for example, emitsArgumentNullException.ThrowIfNull. The injected analyzer config now setsdotnet_banned_api_analyzer.exclude_generated_code = true, which skips files the analyzer recognizes as generated:*.g.csand files with anheader. Hand-written code is still checked.
0.4.2
What's changed
Features
-
A third default-on banned-symbol list,
BannedSymbols.GuardClauses.txt, bans the BCL guard-clause throw helpers and points to theHeadless.Checksguards instead:ArgumentNullException.ThrowIfNull→Argument.IsNotNullArgumentException.ThrowIfNullOrEmpty/ThrowIfNullOrWhiteSpace→Argument.IsNotNullOrEmpty/Argument.IsNotNullOrWhiteSpace- every
ArgumentOutOfRangeException.ThrowIf*→ anArgument.*range guard ObjectDisposedException.ThrowIf→Ensure.NotDisposed
Set
BannedGuardClauseSymbols=falseto permit these helpers while keeping the general and Newtonsoft.Json lists.DisableSupportBannedSymbols=truestill omits all lists.
Analyzer changes
RCS0012(blank line between single-line declarations) is now off. Grouping consecutive single-line declarations, such as a block of fields, is idiomatic C#.RCS0056(line too long) is now off. CSharpier owns line width, and the lines it cannot wrap are string literals and inline suppression reasons that no line-length warning can fix.
Upgrade notes
Projects that call the banned helpers now get RS0030 warnings, which the SDK's CI warning escalation turns into errors. Replace the calls with Headless.Checks guards, or set BannedGuardClauseSymbols=false.
If your repository ejected the editorconfig.txt scaffold into its own .editorconfig, update RCS0012 and RCS0056 there too: a consumer .editorconfig outranks the injected configs.
No runtime API behavior changed; this release changes build-time SDK configuration.
Full changes: 0.4.1...0.4.2
0.4.1
What's changed
Fixes
- xUnit v3 test projects now get
XUNIT_GENERATED_DISABLE_WARNINGS, the constant xUnit actually reads. Since 0.3.5 the SDK definedXUNIT_ENTRYPOINT_DISABLE_WARNINGS, which no xUnit release reads. As a result, analyzer warnings in xUnit's generated entry point were never suppressed and could fail a CI build that treats warnings as errors. xUnit v3 4.0.1 and later wrap their generated entry point and AOT source in#pragma warning disablewhen the constant is defined.EnableXunitEntryPointDisableWarnings=falsestill opts out.
If your code tests XUNIT_ENTRYPOINT_DISABLE_WARNINGS, switch it to XUNIT_GENERATED_DISABLE_WARNINGS.
No runtime API behavior changed; this release changes build-time SDK configuration.
Full changes: 0.4.0...0.4.1
0.4.0
What's changed
SDK behavior
ReportAnalyzernow defaults totrueonly on CI builds. Local and AI-agent builds no longer pay for per-analyzer timing on every compile. AContinuousIntegrationBuildset inDirectory.Build.propsor the project body still turns it on, and an explicitReportAnalyzervalue wins in both directions. Pass-p:ReportAnalyzer=trueto profile analyzers locally.- VSTHRD103 no longer reports synchronous calls that do no I/O and no blocking wait inside async methods: EF Core
DbSet/DbContextAdd/AddRangeandIDbContextFactory.CreateDbContext,MemoryStream/StringReader/StringWriterreads and writes,CancellationTokenSource.Cancel,Timer.Dispose, and xUnit/NUnit assertions over synchronous delegates. The list ships asvs-threading.SyncMethodsToExcludeFromVSTHRD103.Headless.txt; the analyzer merges it with any consumer list namedvs-threading.SyncMethodsToExcludeFromVSTHRD103...txt
Shipped dependency versions
Meziantou.Analyzer3.0.200 → 3.0.290.Microsoft.Sbom.Targets4.1.5 → 4.1.13.Microsoft.Testing.Extensions.CrashDump,HangDump,HotReload,Retry, andTrxReport2.3.3 → 2.4.1.Microsoft.Testing.Extensions.CodeCoverage18.10.0 → 18.11.2.
Analyzer rule review
- Meziantou.Analyzer adds
MA0221–MA0242. All keep their upstream defaults:MA0221–MA0239stay disabled (System.Text.Json strictness, EventSource authoring, and performance hints),MA0240/MA0241act only on a consumer-configured banned-syntax list, andMA0242is informational. MA0212was removed upstream.
Repository tooling
- Built with .NET SDK 10.0.401.
- Updated
MinVerto 8.0.0,Microsoft.SourceLink.GitHubto 10.0.401,Microsoft.Bcl.AsyncInterfacesto 10.0.12, andxunit.v3.mtp-v2to 4.0.1.
No runtime API behavior changed; this release changes build-time SDK configuration and package dependencies.
Full changes: 0.3.5...0.4.0, including PR #54, PR #56, and PR #58
0.3.5
What's changed
SDK behavior
MA0002now reports only non-ordinal string comparisons while remaining a warning.- Package projects now discover
THIRD-PARTY-NOTICESfiles with.TXT,.txt,.MD, and.mdextensions deterministically. - Test projects can set
MinimumExpectedTests; setting it to0omits the SDK-supplied Microsoft Testing Platform guard. - Direct xUnit v3 consumers now receive
XUNIT_ENTRYPOINT_DISABLE_WARNINGSonce, withEnableXunitEntryPointDisableWarnings=falseas an opt-out.
Tooling
- Updated
CSharpier.MSBuildfrom 0.30.2 to 1.3.0 and adopted its current C# and XML formatting contract. - Updated
Meziantou.Analyzerfrom 3.0.177 to 3.0.190. - Reviewed and accepted the upstream defaults for
MA0218,MA0219, andMA0220.
No runtime API behavior changed; this release changes build-time SDK configuration and package behavior.
0.3.4
What's changed
- Updated
Microsoft.CodeAnalysis.CSharp.Workspacesfrom 5.6.0 to 5.9.0. - Updated
MSBuild.StructuredLoggerfrom 2.3.244 to 2.3.246. - Reviewed and accepted Meziantou.Analyzer's informational
MA0216rule when running on the Roslyn 5.9 workspace surface.
No runtime or public API behavior changed.
Full changes: PR #46
0.3.3
What's changed
- Added
Roslynator.Formatting.Analyzers5.0.0 with suggestion-level structural blank-line rules around statements, regions, using lists, declarations, and documentation. - Kept accessor, brace, wrapping, indentation, and blank-line removal rules disabled to avoid conflicts with CSharpier.
- Updated
Roslynator.Analyzersto 5.0.0 andMeziantou.Analyzerto 3.0.177. - Strengthened analyzer package, policy, and scaffolded-editorconfig contract checks.
No runtime or public API behavior changed.
Full changes: PR #44
0.3.2
Changed
- Updated the bundled Meziantou analyzer from 3.0.159 to 3.0.165, adding Roslyn 5.9 support and upstream false-positive fixes.
- Recorded
MA0216at its upstream informational default without changing the SDK severity policy.
No public API or runtime behavior changed. See #43.
0.3.1
Changed
- Refreshed the SDK's shipped test-tool dependency contract: the Microsoft Testing Platform extensions move to 2.3.3 and CodeCoverage moves to 18.10.0. Central pins, SDK-injected versions, and package dependency ranges remain synchronized. (#36, #39)
- Updated the mandatory analyzer bundle to Meziantou.Analyzer 3.0.159 and Roslynator.Analyzers 4.16.1. Newly introduced
MA0213,MA0214, andMA0215rules retain their upstream disabled-by-default severity. (#38, #39) - Updated build dependencies and moved the repository toolchain to the .NET 10.0.400 security servicing release. (#39)
- Updated test SDK examples to xUnit 4.0.0. xUnit remains consumer-selected and is not injected by the SDK. (#39)
No public SDK API or configuration default changed in this release.
Validation
- Linux build, test, and package validation passed.
- Windows and macOS consumer smoke tests passed.
- All six package graphs report no known vulnerable or deprecated direct or transitive dependencies.