feat: replace EOL netcoreapp3.1 target with net8.0 - #23
Merged
Merged
Conversation
The netcoreapp3.1 target causes an assembly built against EOL .NET Core 3.1 to be selected by all .NET 5+ applications, which security scanners flag. Retarget to net8.0, matching the rest of the SDK family. No code changes are needed: Logs.CoreLogging is gated on NETCOREAPP, which is also defined for net8.0.
tanderson-ld
marked this pull request as ready for review
September 21, 2026 20:35
kinyoklion
reviewed
Sep 21, 2026
kinyoklion
reviewed
Sep 21, 2026
kinyoklion
approved these changes
Sep 21, 2026
…amework band Per review: the net8.0 target now floors M.E.L.A at 8.0.3, and the test project uses Microsoft.Extensions.Logging 8.0.1 so tests run against the declared band.
tanderson-ld
pushed a commit
that referenced
this pull request
Sep 22, 2026
🤖 I have created a release *beep* *boop* --- ## [2.1.0](2.0.0...2.1.0) (2026-09-22) ### Features * replace EOL netcoreapp3.1 target with net8.0 ([02a5cf2](02a5cf2)) * replace EOL netcoreapp3.1 target with net8.0 ([#23](#23)) ([4f56f24](4f56f24)) ### Bug Fixes * add release-please version markers to csproj ([4f73aba](4f73aba)) * add release-please version markers to csproj ([#21](#21)) ([903271e](903271e)) * match Microsoft.Extensions.Logging.Abstractions to the net8.0 framework band ([4698802](4698802)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Overview** > **Release 2.1.0** bumps package and release metadata from **2.0.0** to **2.1.0** (manifest, `LaunchDarkly.Logging.csproj`, `PROVENANCE.md` example version, and a new **CHANGELOG** section). > > The release notes capture work already merged for this line: **netcoreapp3.1** is dropped in favor of **net8.0** as a build target (alongside **netstandard2.0** and **net462**), **release-please** version markers were added around the csproj version, and **Microsoft.Extensions.Logging.Abstractions** is pinned to the **8.x** band for the **net8.0** target. This PR itself is the automated Release Please cut—no additional runtime or API code changes beyond those version/doc updates in the diff. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 6b4b25e. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
LaunchDarkly.Logging 2.0.0 still ships a
netcoreapp3.1target. Under NuGet's nearest-compatible asset selection, every .NET 5+ application (including net8.0 services and MAUInet8.0-*apps) selects that asset, so an assembly built against EOL .NET Core 3.1 lands in modern applications. Security scanners flag the EOL runtime references, and this has been reported through customer support as failing CI/CD security gates.This PR replaces the
netcoreapp3.1target withnet8.0, matching the rest of the SDK family (ServerSdk since 8.9.0, CommonSdk since 7.0.1, InternalSdk since 3.8.0). No code changes are required:Logs.CoreLoggingis gated on#if NETCOREAPP, which is also defined for net8.0. Per review, theMicrosoft.Extensions.Logging.Abstractionsfloor on the net8.0 target moves to 8.0.3, the framework-matched band.Related ticket: SDK-3131
Consumer impact
Microsoft.Extensions.Logging.Abstractionsfloor moves 6.0.0 → 8.0.3; scanner finding resolvedLogs.CoreLogging; the LaunchDarkly.Logging.Microsoft package provides the equivalent adapter thereShipped as
feat:(2.1.0), consistent with how the equivalent target-framework changes shipped across the SDK family. (2.0.0 was a major because droppingnet452made the package uninstallable for .NET Framework < 4.6.2; this change leaves every current consumer installable and functional.)Notes for reviewers
<Version>stamp.net10.0target alongside net8.0 is a one-line change that would pre-empt the same scanner issue recurring when net8 reaches EOL (November 2026). Left out here to match current family convention — happy to add if preferred.PackageReference.Testing
dotnet build(0 warnings) anddotnet test(52/52 passed) locally on net8.0/netstandard2.0, includingNetCoreLoggingTestexercisingLogs.CoreLoggingagainst the retargeted asset.Note
Overview
Replaces the EOL
netcoreapp3.1NuGet target withnet8.0so modern .NET apps stop resolving the 3.1 asset (and related scanner failures) while keepingnet462andnetstandard2.0.The
net8.0build now referencesMicrosoft.Extensions.Logging.Abstractions8.0.3 (was 6.0.0 on 3.1); tests useMicrosoft.Extensions.Logging8.0.1.Logs.CoreLoggingstays behind#if NETCOREAPP—only XML/docs and README/CONTRIBUTING examples are updated to describe .NET 8.0+.Reviewed by Cursor Bugbot for commit bb92882. Bugbot is set up for automated code reviews on this repo. Configure here.