Skip to content

Add --min-age option and bump to .NET 10 - #21

Merged
seesharper merged 1 commit into
masterfrom
min-age
Sep 16, 2026
Merged

seesharper merged 1 commit into
masterfrom
min-age

Conversation

@seesharper

Copy link
Copy Markdown
Owner

Closes #20

--min-age / -ma

Holds back package versions that were published too recently.

deps --min-age 2d    # ignore versions published less than 2 days ago
deps --min-age 12h   # ignore versions published less than 12 hours ago
deps --min-age 2     # no suffix, defaults to days

Parsing lives in the new MinimumAge helper. An invalid value prints an error and exits with 1.

PackagesMinimumAge

Project files can specify the same thing, used when --min-age is not passed at runtime.

<PropertyGroup>
  <PackagesMinimumAge>2d</PackagesMinimumAge>
</PropertyGroup>

Resolution is per project file: --min-age wins, otherwise that file's own property. That avoids having to invent a rule for repos where different projects declare different values.

Since we don't evaluate MSBuild, the property only applies in the file that declares it — a value in Directory.Build.props won't reach sibling csproj files, though Directory.Packages.props works fine under CPM since the references live there too. Noted in the README.

How versions get held back

LatestVersionProvider grew a second path:

  • No minimum age anywhere — unchanged FindPackageByIdResource.GetAllVersionsAsync, one latest version per feed.
  • Minimum age in effect — PackageMetadataResource.GetMetadataAsync, which returns every version with its publish date.

Keeping the cheap path matters: the metadata resource pulls full registration pages, so it is meaningfully slower on large packages.

Both paths feed the new PackageVersions type, whose GetLatestVersion(minimumAge, utcNow) picks the newest version published on or before the cutoff. Versions from feeds that don't report a publish date are never held back.

Output

LightInject 7.0.1 7.0.1 (nuget.org) 🍺 (holding back 7.1.0 ⏳)
NuGet.Configuration 6.12.1 => 6.14.0 (nuget.org) 😢 (holding back 7.9.0 ⏳)

A package with no version old enough now reports - no version is older than 2 days ⏳ rather than the misleading "Unable to find package".

.NET 10

All three projects target net10.0, a global.json pins the 10.0 SDK, and CI moves to dotnet-version: 10.0.x with setup-dotnet@v4 / checkout@v4. Versions bumped to 3.2.0 and 2.2.0.

Two calls worth a second look

  • Dotnet.Deps.Core went netstandard2.0 → net10.0. That's what "bump everything" implies, but it's a published library, so consumers on .NET Framework or older .NET lose it. Easy to revert — the code uses no net10-only APIs.
  • IProjectFile<T> gained a member, which breaks external implementers. Hence the Core bump to 2.2.0, though arguably it should be 3.0.0.

The NuGet.* references stay at 6.12.1. They're flagged by NU1901 and 7.9.0 is out, but a 6→7 jump is its own change.

Testing

46 tests pass, 9 new: minimum age parsing and formatting as unit tests, plus end-to-end coverage for the option, the short form, the project file property, precedence between the two, and both invalid-value paths.

🤖 Generated with Claude Code

Adds a --min-age (-ma) option that holds back package versions published
too recently. The value is a number with an optional suffix, 2d for days
and 12h for hours, defaulting to days when no suffix is given.

Project files can specify the same thing through the PackagesMinimumAge
property, which applies when --min-age is not passed on the command line.

When a minimum age is in effect we resolve versions through
PackageMetadataResource so that we get the publish date for every version.
Without it we stay on the cheaper FindPackageByIdResource path, since the
metadata resource pulls full registration pages. Versions from feeds that
do not report a publish date are never held back.

Also bumps all projects to net10.0 and CI to the .NET 10 SDK.

Closes #20

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@seesharper
seesharper merged commit 1fe943e into master Sep 16, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add --min-age argument

1 participant