Runtime: Missing Release Notes for NuGet Packages

Created on 24 Aug 2018  路  10Comments  路  Source: dotnet/runtime

I cannot find any release notes about System.Threading.Tasks.Dataflow release 4.9.0.

The link to https://go.microsoft.com/fwlink/?LinkID=799421 works but i'm not able to find any release notes about any recent version of System.Threading.Tasks.Dataflow.

Possible solutions:

  1. Update the release notes section of the Nuget package to embed or link to the specific release notes for this version.
  2. Create release notes which summarize notable changes from the previous NUget packet version to the new version.
area-Infrastructure-libraries documentation

All 10 comments

@compilenix you can navigate the release note link https://www.nuget.org/packages/System.Threading.Tasks.Dataflow/4.9.0 and then browse to the desired release note. here is some example link listing or commits done in 2.1.3 release https://github.com/dotnet/core/blob/master/release-notes/2.1/2.1.3/2.1.3-commits.md

you can do the same with any other release. I don't think we include in every library package a release note specific to the library, instead, we point to the release notes for the whole net core.

I've seen that there are release notes for the whole net core and it's components, which System.Threading.Tasks.Dataflow is part of.

There are things which makes this really difficult:

  1. I cannot see which version of the package (4.9.0 in this case) coresponses to which net core version and therefore which release notes i have to read.
  2. in the example link for net core 2.1.3 i can't see anything about changes to System.Threading.Tasks.Dataflow or to which NUget package version this belogs.
  3. as far as i can see this, this os not specific to System.Threading.Tasks.Dataflow but also aplies to many other parts / components of net core, i've found multiple places where release notes with slightly varying content are held. I.e.:

None of the links above go into detail about what parts have changed in which way, without reading the commit messages and assosiated issues myself which would be really timeconsuming considering i might be interested in the changes about a single NUget package.

Sorry for the slightly broken language, i'm not a native english speaker^^

@terrajobst @ericstj do you know if we support adding the release notes for every library we support? or we just share the release notes for the whole release?

CC @joperezr

I don't believe we have a good way today to provide release notes to the library granularity.

So there is no reasonable way no know what changed between nuget package releases (i.e. from 4.8.0 to 4.9.0), when they are'nt mentioned in the release notes of dotnet core?

any update?

supei@sandbox-dev-hk:~/workspace/core/release-notes$ rg Pipelines | grep -v Asp
2.1/2.1.0-commit.md:* [`[d08838a]`](https://github.com/dotnet/corefx/commit/d08838a) More ValueTask goodness for System.IO.Pipelines (#27701)
2.1/2.1.0-commit.md:* [`[8958ef9]`](https://github.com/dotnet/corefx/commit/8958ef9) ValueTask adoption in System.IO.Pipelines (#27651)
2.1/2.1.0-commit.md:* [`[a32de71]`](https://github.com/dotnet/corefx/commit/a32de71) Fix System.IO.Pipelines reference assembly (#27644)
2.1/2.1.0-commit.md:* [`[ef8ed75]`](https://github.com/dotnet/corefx/commit/ef8ed75) Cross compile Pipelines and retarget ref to netstandard1.1 (#27166)
2.1/2.1.0-commit.md:* [`[5573f26]`](https://github.com/dotnet/corefx/commit/5573f26) Add System.IO.Pipelines
2.1/2.1.0-commit.md:* [`[2148656]`](https://github.com/dotnet/corefx/commit/2148656) Add System.IO.Pipelines
2.1/2.1.7/2.1.7.md:System.IO.Pipelines | 4.5.3
2.1/2.1.4/2.1.4.md:Microsoft is aware of a denial of service vulnerability in .NET Core when System.IO.Pipelines improperly handles requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an application that is leveraging System.IO.Pipelines. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by providing specially crafted requests to the application.
2.1/2.1.4/2.1.4.md:The update addresses the vulnerability by correcting how System.IO.Pipelines handles requests.
2.1/2.1.4/2.1.4.md:System.IO.Pipelines | 4.5.0 | 4.5.1 |
2.1/2.1.4/2.1.4.md:System.IO.Pipelines | 4.5.0 | 4.5.1
2.2/2.2.0/2.2.0-commits.md:* [`[d69ef185c3]`](https://github.com/dotnet/corefx/commit/d69ef185c3) Updated the package version for System.IO.Pipelines to 4.5.1

CC @karelz @danmosemsft

@compilenix I don't think anything changed since last reply you received from @joperezr. We are not including the release notes per package and instead we have release notes for the whole release. We may look at that in the future but don't expect this will change for 2.1 release.

OK, thanks for the response @tarekgh :)

Was this page helpful?
0 / 5 - 0 ratings