Skip to content

Bump Scriban from 6.2.1 to 7.2.6 - #1877

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/nuget/Scriban-7.2.6
Closed

Bump Scriban from 6.2.1 to 7.2.6#1877
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/nuget/Scriban-7.2.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Contributor

Updated Scriban from 6.2.1 to 7.2.6.

Release notes

Sourced from Scriban's releases.

7.2.6

Changes

✨ New Features

  • Add NuGet Trusted Publishing via dotnet-releaser (ebb0c638)

🐛 Bug Fixes

  • Fix missing tests (c3f03bfc)

📦 Dependencies

  • Bump deps (a1caafbe)

🧰 Misc

  • Enforce LoopLimit for lazy array multiplication (973edd1f)
  • Avoid work when multiplying empty strings (9fe9627b)
  • Enforce LoopLimit when expanding indexed arrays (41c27a18)
  • Share LoopLimit across nested iteration (d17bd4bf)
  • Allow platform-specific parser depth guard (420513a9)

Full Changelog: 7.2.5...7.2.6

Published with dotnet-releaser

7.2.5

Changes

🧰 Misc

  • Allow nulls in nullable builtin functions (88729199)

Full Changelog: 7.2.4...7.2.5

Published with dotnet-releaser

7.2.4

Changes

🐛 Bug Fixes

  • Fix build warning (4ca0455a)

🧰 Misc

  • Clarify URL escaping semantics (99cc7c61)

Full Changelog: 7.2.3...7.2.4

Published with dotnet-releaser

7.2.3

Changes

🧰 Misc

  • Document safe include file loading (34d1cd12)
  • Restrict reflected writes to public setters (c7377a60)

Full Changelog: 7.2.2...7.2.3

Published with dotnet-releaser

7.2.2

Changes

🐛 Bug Fixes

  • Fix parametric function variable scope (#​676) (54b781ec)

🧰 Misc

  • Clarify variable scope documentation (390db7ff)
  • Clarify MemberFilter sandbox limitations (29294e1b)

Full Changelog: 7.2.1...7.2.2

Published with dotnet-releaser

7.2.1

Changes

🧰 Misc

  • Limit array multiplication growth (205ca6a7)
  • Stop parsing at expression depth limit (8fdbd687)
  • Document member filters as reflection-only (d45f7f03)

Full Changelog: 7.2.0...7.2.1

Published with dotnet-releaser

7.2.0

Changes

🐛 Bug Fixes

  • Fix readme with source embedding (#​671) (c8094b09)

🧰 Misc

  • Merge commit from fork (7fdf19df)

Full Changelog: 7.1.0...7.2.0

Published with dotnet-releaser

7.1.0

Changes

🐛 Bug Fixes

  • Fix System.Text.Json to use 9.0.14 instead (Fixes #​668) (41e94911)

🧰 Misc

  • Added DateTime.UtcNow Support (PR #​667) by @​boslandj

Full Changelog: 7.0.6...7.1.0

Published with dotnet-releaser

7.0.6

Changes

🐛 Bug Fixes

  • Fix runtime polyfills (#​665) (37f226ac)

🧰 Misc

  • Document TemplateContext runtime controls (32ce64cd)
  • Use GitHub alerts in documentation (5946a931)
  • Remove H1 headings from site docs (73895d33)

Full Changelog: 7.0.5...7.0.6

Published with dotnet-releaser

7.0.5

Changes

🐛 Bug Fixes

  • Fix include indentation after newline (60ab0d94)

Full Changelog: 7.0.4...7.0.5

Published with dotnet-releaser

7.0.4

Changes

🧰 Misc

  • Remove duplicated runtime attributes (e8b19f66)

Full Changelog: 7.0.3...7.0.4

Published with dotnet-releaser

7.0.3

Changes

🐛 Bug Fixes

  • Fix IsPackable for CheckSourceEmbedded.csproj (3f49de50)

Full Changelog: 7.0.2...7.0.3

Published with dotnet-releaser

7.0.0

Changes

✨ New Features

  • Add security tests for untested protection paths (570466a4)
  • Add AOT/trimming compatibility (#​656) (a58550f1)
  • Add nullable support (e5f6950f)
  • Add public comments to generated visitor code (035db9a3)

🐛 Bug Fixes

  • Fix TemplateLoader doc reference (73271543)
  • Fix delegate optional defaults (a12cd0ba)
  • Fix null-conditional indexers (e4693e77)
  • Fix AsyncCodeGen solution lookup (d56dc4e1)
  • Fix pipe argument docs (4cb135ab)
  • Fix generator execution after nullable support (de47d8ad)
  • Fix Scriban.props and ci (ebfc4054)
  • Fix NU5129 as no-warning (25d148a1)

🧰 Maintenance

  • Update ci (bafc1b5b)

🧰 Misc

  • Remove changelog.md (8939dde5)
  • Harden string padding width limits (4227fdee)
  • Bound object.to_json recursion and cycles (760dc212)
  • Enforce parser depth for array initializers (f55280a0)
  • Clear include cache on TemplateContext.Reset (099cb049)
  • Reset typed accessor cache with MemberFilter changes (8180fb6c)
  • Enforce cumulative output size limits (98563216)
  • Harden expression evaluation resource bounds (2d01bd15)
  • Apply LoopLimit to internal iteration paths (dde661d3)
  • Sync builtin overload docs with DocGen (b6c65c79)
  • Disable STJ for source-embedded builds (9abb65bb)
  • Enforce LimitToString in string Append, Prepend, Replace, ReplaceFirst (d3841086)
  • Await async model members (ecca082b)
  • Update follow-up plan (2f99ca64)
  • Make array.sort stable (b3571666)
  • Support dotted array.sort paths (1df80f77)
  • Finalize follow-up plan (3ec006c9)
  • Remove completed issue plan (8557aadf)
  • Update deps (3f080790)
  • Change LexerOptions / ParserOptions to record (0c229175)
  • Remove Nustache (f2ea38fa)
  • Update readme (b3f915e5)

Full Changelog: 6.6.0...7.0.0
... (truncated)

6.6.0

Changes

✨ New Features

  • Add missing async generated code (8d23abb0)
  • Add limits for default safety (b5ac4bf3) by @​skdishansachin

🐛 Bug Fixes

  • Fix JsonElement support for netstandard (88943520)

🧰 Misc

  • Merge commit from fork (a6fe6074) by @​skdishansachin

Full Changelog: 6.5.8...6.6.0

Published with dotnet-releaser

6.5.8

Changes

🚀 Enhancements

  • Evaluate named arg. values in caller context (PR #​652) by @​meld-cp

🧰 Misc

  • Cleanup Include remove magic checks (PR #​651) by @​Benkei

Full Changelog: 6.5.7...6.5.8

Published with dotnet-releaser

6.5.7

Changes

🚀 Enhancements

  • Refactor Include using PushLocal and PopLocal Part 2 (PR #​650) by @​Benkei

Full Changelog: 6.5.6...6.5.7

Published with dotnet-releaser

6.5.6

Changes

🐛 Bug Fixes

  • Refactor Include using PushLocal and PopLocal (PR #​649) by @​Benkei
  • Fixes documentation (#​647) (6513395f)

🧰 Misc

  • Feature/#​645 broken link (PR #​646) by @​mikeclayton

Full Changelog: 6.5.5...6.5.6

Published with dotnet-releaser

6.5.5

Changes

🐛 Bug Fixes

  • Fix Include named arg values being lost for nested includes (PR #​643) by @​meld-cp

Full Changelog: 6.5.4...6.5.5

Published with dotnet-releaser

6.5.4

Changes

✨ New Features

  • Add instructions (6ccb65f3)
  • Add site (f9afab3e)
  • Add Scriban.AppService playground backend (b1072d73)
  • Add social banner (11cbacaf)
  • Add ScriptArray.From() static factory method (4b3f0417)

🐛 Bug Fixes

  • fix date.parse test with 'Z' not working if local timezone > UTC+03:00 (PR #​642) by @​meld-cp

📚 Documentation

  • Add doc for runtime by splitting existing doc (ce0a2b60)

🧰 Misc

  • include template - Named array args don't stay as arrays in the template (PR #​641) by @​meld-cp
  • Redirect Try out links to site playground, support URL parameters (0592e64c)
  • Update readme for the online demo (5b9f5113)
  • Use dark theme (18331e9a)

Full Changelog: 6.5.3...6.5.4

Published with dotnet-releaser

6.5.3

Changes

🐛 Bug Fixes

  • Fix setting variable in a scope while it is also declared in an outer scope (577e2d47)

📦 Dependencies

  • Bump Scriban to net8.0 (fc29ec64)

🧰 Misc

  • Update date.now in tests for 2026 (f00a6bbf)

Full Changelog: 6.5.2...6.5.3

Published with dotnet-releaser

6.5.2

Changes

🐛 Bug Fixes

  • Fix #​634: ObjectToString has side-effect leading to incorrect escaping with lazy evaluation (PR #​635) by @​anya-hichu

Full Changelog: 6.5.1...6.5.2

Published with dotnet-releaser

6.5.1

Changes

🐛 Bug Fixes

  • Fix async code for promoted variables (ac6a80aa)

🧰 Misc

  • Migrate to slnx and central package management (63bc3d61)

Full Changelog: 6.5.0...6.5.1

Published with dotnet-releaser

6.5.0

Changes

🐛 Bug Fixes

  • Fix Liquid date output formatting (PR #​627) by @​meld-cp
  • Update ScriptBinaryExpression.cs (PR #​630) by @​marcelo8690

Full Changelog: 6.4.0...6.5.0

Published with dotnet-releaser

6.4.0

Changes

🚀 Enhancements

  • Promote named args to local vars when using includes (PR #​626) by @​meld-cp

Full Changelog: 6.3.0...6.4.0

Published with dotnet-releaser

6.3.0

Changes

🐛 Bug Fixes

  • Fix loop limits (#​616) (b9a64f79)
  • Fix newline_to_br function on Windows (5c6e39ad)
  • Fix uint (6fda3a5e)

🚀 Enhancements

  • Update BuiltinFunctions.cs: set correct initial capacity (PR #​621) by @​ChrisVanDijk
  • Update TemplateContext.cs: remove unused _availableTags (PR #​623) by @​ChrisVanDijk
  • Add uint calculation (PR #​624) by @​dunds-com

📚 Documentation

  • Update alert messages in readme to be more obvious (PR #​619) by @​JackGilmore
  • Fix doc generation (67d5494b)

📦 Dependencies

  • Update dependencies NuGet (c8eaa485)

Full Changelog: 6.2.1...6.3.0

Published with dotnet-releaser

Commits viewable in compare view.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 5, 2026
@kubernetes-prow kubernetes-prow Bot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Aug 5, 2026

@tg123 tg123 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/LGTM

@kubernetes-prow kubernetes-prow Bot added lgtm "Looks good to me", indicates that a PR is ready to be merged. approved Indicates a PR has been approved by an approver from all required OWNERS files. labels Aug 8, 2026
@tg123

tg123 commented Sep 1, 2026

Copy link
Copy Markdown
Member

/LGTM

@kubernetes-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: dependabot[bot], tg123

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

---
updated-dependencies:
- dependency-name: Scriban
  dependency-version: 7.2.6
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Looks like Scriban is no longer updatable, so this is no longer needed.

@dependabot
dependabot Bot force-pushed the dependabot/nuget/Scriban-7.2.6 branch from a9f4b64 to 4b80c77 Compare September 1, 2026 19:00
@dependabot dependabot Bot closed this Sep 1, 2026
@kubernetes-prow kubernetes-prow Bot removed the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Sep 1, 2026
@kubernetes-prow

Copy link
Copy Markdown

New changes are detected. LGTM label has been removed.

@dependabot
dependabot Bot deleted the dependabot/nuget/Scriban-7.2.6 branch September 1, 2026 19:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. dependencies Pull requests that update a dependency file size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant