
Sign up to save your podcasts
Or


Between the SolarWinds hack, Microsoft releasing a working document detailing the problems with the .NET ecosystem, and a bouncy castle crypto vulnerability, it's been a busy week. Let's dive in and see what happened, shall we?
π€Ό Immo Landwerth, PM for .NET, writes a document on the eco-system problems in .NET. This document is monumental in it being a candid take on the .NET OSS ecosystem problem; and while it says it softer than I will, it lays the blame for the state of the .NET Ecosystem on Microsoft. Building Trust with your community is the first step to solving any problem (and let's be clear: Building trust if-you-don't-already-have-it should always be the first step) and this document does just that. Microsoft is its own worst enemy when it comes to building a sustainable eco-system for .NET. Luckily they're at least aware of the problem. There's also a github issue devoted to feedback on The Document and you should chime in if you have passionate thoughts on the subject. I know I do.
β¬ .NET Core updates are coming to... Microsoft update (not Windows Update!). Well, not exactly. Client updates will happen through "Automatic Updates", server updates will happen via WSUS and Microsoft Update. Somewhere a sysadmin is crying.
π¨ the Bouncy Castle project has a vulnerability in its authentication module which allows attackers to very easily figure out the hashed passwords. The flaw? It checks that the characters exist in the string instead of checking that the characters are at the correct index. Hugops to the Bouncy Castle team.
π©βπ» Not to be outdone by Apple, Microsoft is designing its own ARM Chips for its servers and Surface PCs. No amount of designing your own chips will get Microsoft out of the "We must support all of our software from the beginning of time" problem they've created for themselves, and that problem is central to why "just making ARM chips" won't make things better. Maybe this is the business person in me talking; but perhaps some of these 25 year old applications need to be re-written off of Win32?
π CodeMaze walks through using Authentication in ASP.NET Core with Angular. I got excited for a second when I thought they were going to cover authorization, but no. No one covers Authorization. Authorization is like married couple sex. You know people do it, but you never see it and they really don't talk about how they do it that much.
β You can win $250 US dollars by taking part in the .NET Foundation "State of .NET" survey. Yes, I have jokes, but I'll put those aside for a second to say: You should take this survey. The .NET Foundation needs to hear what you find important, and they need you to be as direct about it as possible. Also, how can Microsoft possibly figure out which open source project to torpedo next if you don't tell them what you're using?
π¨π¨π¨ The Solarwinds DLL used to hijack systems "Solarigate" was catalogued last week by the folks at Microsoft. In case you missed that fun, Nation state-level hackers found the deployment credentials for Solarwinds updates on Github; engineered an update with a malicious payload inside of it, got into a few dozen government agencies networks, used that payload to install backdoors and laterally move into other systems, and all the while kept it secret for 9 months. This post goes deep into an analysis of that DLL.
π Lesley Carhart writes up her own thoughts on the SolarWinds attack. No snark here, Lesley is one of the smartest infosec people I know, and her commentary is always helpful in these trying times (gestures broadly).
π₯ Remember when movie tie-ins were terrible video games? Now it's using the movie to tech people how to code, and we're all the better for it. Space Jam: a New Legacy is coming out, and why not use it to teach people how to code?
π Xamgirl shows you how to implement Multi-binding in Xamarin forms blog posts on Xamarin are the programmer's equivalent of a gym membership. I read them, and I really want to pick up Xamarin forms; but then I have Ionic sitting right there and I just don't do it. I can just read the blog posts and learn Xamarin vicariously through that; right?
π Telerik reminds you of 10 things you probably didn't know about Blazor Not covered on the list is that Blazor is the programming language for stoners; and it represents an underground attempt to make Mary Jane mainstream. Sign. I can't do it. I can't write satire about QAnon without it sounding completely nuts and completely plausible that someone thinks that all at the same time.
π So there's a blog post by David Pine that shows you how to make localization using machine generated translations using Azure Well that's pretty flipping neat.
π€Ό The team working on System.Text.Json details what's next. Given that Newtonsoft.Json is functionally stable and doesn't seem to be getting many more updates, it doesn't make a whole lot of sense for teams looking for new Json serialization to use Newtonsoft.Json, and so we may as well embrace what Microsoft has created here.
π¦ David fowler shares his progress on improving Http.sys for teams migrating from .NET Framework to .NET core, and given the age of the code in question; this PR serves as a really good way to see how to make performance improvements to code that's almost 20 years old.
π Dotnet Rocks interviews Laura Laban, CEO of InfiniteFlight on her product InfiniteFlight, which is a .NET and C# mobile flight simulator. Yes, a mobile flight sim written in C# and using .NET. That alone is amazing.
π¦ Nick Craver, Architecture Lead at Stack Overflow, deep dives into a mysterious bug the Stack Overflow team was running into and they found what was causing it it. Stack Overflow runs on .NET 5; and this twitter thread is about as close as you can come to "being along for the ride". Well worth your time to read.
πΈ Microsoft Changes its certification programs and makes them free, but you have to renew them yearly This isn't so bad, especially given the rate of c...
Skip to contentΒ
Β Pull requests Issues
Β Marketplace Explore
gortok/ lwidn-newsletterPrivate
Β 1Β
Β 0Β
Β 0Β
Code
Issues
Pull requests
Actions
Projects
Security
Insights
lwidn-newsletter/LwidnGenerator/input/20201212.md
gortok Update 20201212.md
This is Last Week in .NET for the week ending 12 December, 2020.
π’ .NET 5.0.1 has been released. Lots of Bug Fixes and Performance improvements in this one; with an focus on EFCore. If you use EF Core, take note.
π¨ There's a Remote Code Execution Vulnerability in MS Teams that was apparently patched in October 2020. This github repository includes commentary and videos on the RCE itself. The important point here (besides it being patched) is that according to Microsoft, it's not a very dangerous RCE, but from the outside looking in, a "zero-click, wormable, cross-platform remote code execution in Microsoft Teams" seems pretty dangerous. The problem with bug bounties and patching systems is that the incentive is to give out as little money as possible, and once the vendor is aware of the bug, the leverage is gone, couple that with the legal fragility of saying "I have a way to hack into your systems", and you have a recipe for disaster.
π₯ Microsoft's ASP.NET Community standup covers "Material Design with Blazor", which continues the tradition of tech parroting tech. Alternate Runtime that compiles to JavaScript? Check. Design library that mimics a flat design? Check. All we're missing is a realization that in 5 years, Material design made design worse, not better, as we all relegate flat design to the dustbin of bad decisions, where it belongs.
π₯ Did you know Microsoft has its own TV station devoted to .NET? The Zoomers are probably asking "What's a TV Station?" but for the rest of us, .NET live is effectively a TV station devoted to... .NET. This is precisely as exciting as it sounds, and that excitement you feel is why you subscribe to my newsletter.
π¦ Scott Hanselmen reminds us, If you're using .NET Core, you can generate a .gitignore file in one command dotnet new gitignore will generate a .gitignore file that is already set up for working in .NET. This is a pretty neat development and I'm here for it.
π Jetbrains tells you how to make the most of init-only properties and records with Resharper 2020.3 and C#9. ReSharper remains one of the fastest ways to improve your productivity in Visual Studio. Even with VS 2019, which has come a long way in refactorings, ReSharper still beats Visual Studio's out of the box developer experience, hands down.
π©βπ» There are cryptography improvements in .NET 5 for the 5 of you that care about this, you probably already know about it. So really the only thing I can say is "Don't roll your own crypto" and "don't trust some random blog post on Crypto", and let's all ignore for the second that this blog post filled the latter. In all seriousness though: If your code even comes within 50 feet of dealing with Cryptography, hire an "InfoSec" centered developer that knows what they're doing.
β© If you use blazor, there's a library that claims to have somewhere between "0-1000x faster API responses on server side with Fusion's caching and automatic dependency tracking abstractions.". Yes, 0-1000x. That's quite the range. This is one of those situations where I'm thinking "Ok, this could be bullshit", or "I'd love to interview the developer of this to get a better understanding of what's going on", so if you run the Stl.Fusion project, or you know who does, make me an introduction?
π€Ό Github Universe took place last week and there are lots of on-demand sessions available for your perusal. Oh, and drop ICE as a contract, please. Best, Me.
π
Normally I'd start this out with some of the funnier things that happened; but before I dive into what happened last week, I want to talk about this week.Β
Warning: death and violence follow.
Β
Yesterday was the 31st anniversary of the Γcole Polytechnique massacre. If you're not familiar with this atrocity, let me quote Deb Chachra's chilling telling of the event:Β
He then opened fire on the women, killing six of them. Then he went from floor to floor in the building, targeting and shooting women.
Fourteen women were killed that day, twelve of them engineering students, one a nursing student, and one a university employee.
Here are their names: Anne St-Arneault, Geneviève Bergeron, Hélène Colgan, Nathalie Crotea, Barbara Daigneault, Anne-Marie Edward, Maud Haviernick, Barbara Klueznick, Maryse Laganière, Maryse Leclair, Anne-Marie Lemay, Sonia Pelletier, Michèle Richard, and Annie Turcotte. (Me: You can hear more about these women here.)
An additional thirteen people were injured. Nathalie Provost was shot four times, but survived. In the weeks, months, and years that followed, among other responses, Canada implemented stricter gun-control regulations, and began to observe December 6th as a National Day of Remembrance and Action on Violence Against Women. The event remains the worst mass murder in Canadian history.
Our industry has problems with sexism, whether latent or outright. While we hope never to have another atrocity like this one; we should strive for equality and justice in our industry. As a white dude in tech, I'll do everything I can; and I ask you to do the same. If you've never had to fear for your life just because you wanted to be an engineer, then you too need to stand up and help stop the sexism in our industry.
Β
Now, on to what happened last week in the world of .NET.
Β
π Christina Warren (@film_girl on twitter) submitted a feature request for Windows Terminal to include a "Stories" feature. It was closed far too quickly, in my option, and we all know how hard it is for Microsoft to design a terminal. This would be a nice way to include video tips about the terminal in the terminal itself. What could go wrong?
π If you're the type of developer that has a need to monitor the Garbage Collector, you should read about the newly updated in .NET 5 GC.GetGCMemoryInfo API from Maoni Stephens. We're all in the boat where we don't want to deal with the Garbage Collector until we need to deal with the garbage collector, so read this post, and save it for a rainy day.
π Code-Maze continues their blazor series with a post on one-way and two-way binding in blazor applications. I maintain that two-way binding is evil and should be avoided at all costs. Think I'm wrong? Yell at me on Twitter @gortok.
π How to Unit Test in Entity Framework Core 5 by Michal Bialecki. My preferred answer is: "Don't unit test persistence". Thank you for coming to my TED Talk.
π₯ The Visual Studio team livecasted a Remote office Hours talking about the future architectural changes being made to Visual Studio Visual Studio is older than most college seniors these days, and it's spectacular to see it still alive and kicking. It is probably the best in class IDE I've ever used, and probably the nicest product Microsoft has ever developed for a technical audience.
π MVVM Toolkit Preview 3 has been released. Deeper dive into this is that Michael, the author of this blog post, deep dives into the API. I'm not quite sure what the MVVM Toolkit is for; it looks like some sort of platform-independent MVVM library. Special thanks to Dee Dee Walsh, @ddskier on twitter for the link.
π There's an open feature request to get IDE support for Preprocessor symbols. YES. PLEASE. That is far better than the current state of: "What did we name that IFDEF? I don't know. Guess I'll just guess and have a timebomb waiting to blow up in my face."
π Paul Sheriff talks about what's new in .NET 5 on the Azure DevOps podcast. I checked, and they did start this podcast after TFS was renamed to Azure DevOps. I hope they're comfortable with change because the name "Azure DevOps" reminds me of 70s disco. It's cute but it's gonna get old fast.
π Kalid Abuhakmeh talks about Module Initialization in C# 9. If, like me, you have no idea what this is, you can probably skip it. But if your team bandies about "Secure coding" and "Threat Model" as terms of art, you may want to read this post. Basically it gives you a way of loading environment variables or code before your your code gets run.
π§ͺ Microsoft is testing Windows Feature Experiance Pack updates with Windows Insiders. The Windows Feature Experience Pack, so named because Microsoft's Marketing department has a minimum character limit quota; includes improvements to windows. In this case, an updated Snipping tool, text input panel, and a suggestion feature for the windows shell. According to this article, Microsoft wants to make future improvements to the.... Feature experience (Sorry not sorry) available through this... pack. If you are A Windows Insider, let me know how you like these updates.
π° Microsoft Teams adds support for answering calls via Apple Carplay, transferring calls between mobile and desktop, and adding call recordings to onedrive. Oh for fucks sake. Instead of someone saying "You know what? Enough is enough. This "Work from anywhere while you're doing anything is nucking futz and we aren't going to do it any more. The eight-hour workday is hereby abolished for a four-hour workday that you'll actually be able to make it through and still get things done. I've never seen technology workers productive for an entire 8 hour day; and it's about time we stop pretending that they will be.
π₯
Welcome to Last week in .NET; and last week was a holiday week so things will be lighter than usual.
π Matthew Jones talks about Expressions, Lambda, and Delegates in simpleΒ terms. Lambdas were one of the hardest concepts for me to learn; and 12 years later, I'm glad I did.
I still don't use Func and Action to the extent I've seen in other codebases; but that's because I don't want the maintenance programmer to hunt me down.
π Why does JavaScript use 0 as January and 11 to denote December? Good @&*#ing question. Good news, is Hillel Wayne dove into old unix systems to find the answer. If you don't follow Hillel's work, you should.
π₯ David Fowler Deep Dives into the ASP.NET Core architecture. This is an incredible deep (and I mean deep) dive into the reasons why the ASP.NET Core framework behaves the way it does; provides a nice history of where we came from, and reiterates that the MVC framework is a framework for frameworks.Β
π Do you write nuget packages? If so, you should know about the NuGetPackageExplorer. Also apparently it can help you find incorrect configurations for your packages
π Want to use C# 9 for your Xamarin projects? James Montamagno tells you how. For most of us, we're still waiting for .NET 6 MAUI to unify the runtimes.
π Dave A Brock shows you how to isolate and test your service dependencies in Blazor. This addresses one of my chief concerns about blazor; and it's good that there are people minding the testing store.
π’ Visual Studio for Mac 8.8 now supports NuGet 5.8 The dirty secret about Visual Studio for Mac is that it's MonoDevelop reskinned; and it has a long way to go to match the power of Visual Studio for Windows; but I'm glad for Microsoft putting effort into a Mac client.
π Do you like VB.NET, Winforms, and .NET 5 I'm sorry, I'm sorry, and good! Kidding aside; Winforms is still the way to build a line of business desktop application; and chances are if your business is at least 20 years old you have a lot of internal applications written in at least one of the three. Anyway, this blog post goes into how you can use all three together in .NET 5.
π Versioning your .NET code doesn't have to suck. How many times have you created a custom build script to versioning your releases? Do you use Git? Do you want to stop writing custom code to do this thing that should be available out of the box? Andrew Arnott has your back with NerdBank.GitVersioning.
π΅οΈββοΈ Microsoft wants to make sure your employer knows when you're working and when you're slacking off. Microsoft has added a feature to allow you to calculate "productivity scores" for your 'team members' in Office 365, and there's no word whether or not it compensates for productivity loss caused by Microsoft's own terrible UI choices.
π Immo Landwerth (PM on the .NET Team), makes a funny about Microsoft naming: "People still complain about the .NET Core naming. Just keep in mind that it's named by Microsoft so it's a miracle we didn't call it ".NET Framework without AppDomains, Remoting, and most of WCF but for multiple operating systems as long as you promise to run your cloud on Azure". Yea, that about sums it up.
π How to implement CSS Isolation in .NET 5's Blazor You now get "CSS Isolation" in blazor. What that really means is that now in Blazor, you can have CSS scoped to a component, just like in Angular (and probably other SPAs). This is a fundamental feature for SPAs, and I'm surprised it wasn't in 1.0. π€― Do you have Assembly version conflicts? Trick question: We all do. Good news is that there's an in-depth blog post that will help you resolve these issues and restore your sanity.
π Andrew Lock has a preview from his new book about how to apply the MVC design pattern to Razor Pages. It's a bit of shoehorning, but let's go with it.
π There's an F# newsletter out with what's new there F# is a great language; but I don't spend a lot of time in it.
π Scott Hanselmen shows you how to create a Self-Contained Deployment with Single file Publish and Winforms on .NET 5 This is crucial for Desktop applications and far overdue. I hope this rekindles interest in desktop applications.
There's a breaking bug change with .NET 5 and VB.NET that will cause you problems if you run into it. Be careful if you use VB.NET .? OR GreaterThan, And AndAlso; and my apologies to you if you're listening to this instead of reading it.
π There's a comic about Debugging tactics and how often we use them For some reason "The Ballmer Peak" wasn't listed. I consider this an error.
And that's what happened last week in .NET. It was the American Thanksgiving Holiday, and I hope you and yours enjoyed it. I'll see you next week.
π’πVisual Studio 16.8 has been released; and it might have uninstalled the .NET Core 3.1 SDKs on your behalf.
π²Random Street View shows you a place in the world randomly. Hopefully this gives you something fun to do during this holiday week while waiting for the clock to hit 5pm.
π’ Do you like the idea of using C# for scriptiong? dotnet-script provides that. Personally I'm of a mind that they should have modified C# for Scripting a long time ago and not invented Powershell, but we don't all get what we want.
π Github reverses course and re-enables the youtube-dl repository. The RIAA had issued a takedown notice; since the youtube-dl repository allows for command line accesss to Youtube. Initially Github caved (because they thought they had to?) and removed the repository; but after the Electronic Frontier Foundation (EFF) stepped in with a supporting letter as to why the RIAA was mistaken in their claim, they re-enabled access to the repository.
π If you have a class with a private default constructor in .NET 5; SignalR can't deseralize it. The author of this blog post suffered so we wouldn't have to.
π AppVeyor has a helpful (short) blog post on Version pinning for .NET 5 and the .NET Core SDK.
π’ .NET Framework November 2020 Security and Quality Rollup Updates have been released. This is a release of the "Preview" I mentioned a few weeks ago; although the word 'security' is in the title, there aren't any security updates in this release.
π€¦β Jimmy Bogard released a galaxy brain meme on how to see if a string is null in C# It's pretty extensive.
π You can see all the differences between the .NET Standard 2.1 and .NET Core 3.1 APIs vs .NET 5 here. It's pretty cool to see all the API differences in one place.
π Roadmap for WinUI 3 should be out in the first half of 2021. I've said this before and I'll say this again: I have no idea what WinUI is or how it's different from all the other UI strategies Microsoft has had; but maybe we'll get lucky and it'll finally unify everything.
π’ Along the same vein, WinUI 3 Preview 3 has been released.
π Julie Lerman shows you how to deploy containerized .NET 5 applications using AWS's fargate. Also maybe one day AWS will unify its containerization strategy.
π₯ Monsters weekly releases a video on how C# 9's Pattern Matching can make your job as a developer easier.
π₯ There's a new Git Experience in Visual Studio 2019 16.8. If you use the UI; let me know how much better it's gotten.
π‘ Exception Filters allow you to pare down what you're catching, and as the old adage goes, if you can't handle it, don't catch it.
π‘ Microsoft edge allows you to add 'notes' to a PDF document Keep this up, Edge and I may install you on my PC.
π Top 5 features of EF Core 5.0 from 4 Entity Framework Experts. While we're running the numbers, it turns out there were 240 enhancements, 380 bug fixes, and around 200 updates to documentation, and to give you an idea, EF Core 3.1 was released On 3 December 2019; so all those changes were made in the span of 11 months.
π The Roslyn team wrote a blog post detailing what's new in the .NET Productivity Realm If you use Visual Studio 2019, it's worth your time to check this out since you're likely to find something to help you out.
π Joseph Guadagno shows you how to add .NET 5 support to the Azure App Service I'm not sure why this is a thing we as developers have to do; but here we are.
π’ Microsoft Research released a fuzzing tool for HTTP and REST APIs. A fuzzer is a real life incarnation of the saying "Throwing spagetti at a wall and see what sticks".
π’ TypeScript 4.1 has been released. Here's my periodic reminder to you that TypeScript does not respect SemVer and therefore not pinning to the exact version of TypeScript you're using (major.minor.patch) is a good way to cause random build breakages whenever typescript releases a new version.
π‘ Don't use the TFM without the SDK, says .NET team. Basically if your TFM is readable, you're not using the right thing. Include both the TFM and the SDK number so you're pinned to the exact right thing.
π’ Microsoft.Data.SqlClient 2.1 has been released with lots of bug fixes and performance improvements -- and they mean it this time.
π’ Microsoft's WebView 2 now uses Chromium Edge for when you need an integrated web browser in your .NET application The joke here is that we're stuck with Desktop UI toolchains but we'd all rather be using web toolchains.
And lastly,
π Explaining Chains, Funcs and Actions in C#. Honestly this all sounds a bit like a kink; but I assure you, it's all SFW.
π’ .NET 5 has been released. As a reminder, .NET Framework 4.8 is the last, and dare I say, legacy version of .NET. .NET 5 is .NET Core 3.1 renamed to .NET, so that going forward -- at least in name, .NET is unified. .NET 6 will actually unify all the different frameworks under the umbrella of .NET, but 5 is the aspirational name change.
As a minor note, ASP.NET Core on .NET 5 is the name for ASP.NET Core. It works, as long as you don't think about it too hard. Also "Core" is an overloaded term now. Enjoy!
π With .NET 5, "Single File Applications" are now Generally Available. A single file application is not what it sounds like because naming is hard. 'File' here means 'output file', not source code file (that will become important in a minute). With .NET 5 you can now deploy a statically linked executable that contains the runtime and everything it needs in a single file. If you've created a Go application, this is that. Also note that it appears they've now changed the name from "Single file application" to "Single file Deployment", which is a good name change in my opinion.
π Also with .NET 5, you can now have a... sigh.. single source code file application with what the .NET team calls "Top Level Statements". Instead of the ceremony with static void main; you can just start diving in to the code and it'll just work.
.NET 5 will not offer replacements for ASP.NET Webforms, WCF, Windows Workflow Foundation. If you want to adopt .NET 5, then you'd need to look at their alternatives; which are ASP.NET Core Blazor, gRPC, and Open-source CoreWF respectively. I feel bad for the half of you that will never be able to adopt .NET 5 because your business is running on Webforms and there is no upgrade path without a rewrite.
π System.Text.Json Aka Microsoft's "Newtonsoft Json replacement" has got some new features. If you're adopting .NET 5, you're going to want to pay attention, as Newtonsoft.Json is no longer being developed. If you are just catching up, they hired JNK about a year ago and quickly put Newtonsoft.Json out to pasture. System.Text.Json is your new replacement.
π C# 9 records are now generally available. A record is a way to effectively have an (almost) immutable DTO without all of the ceremony that DTOs used to take. If you have a property-based object with no behavior (methods), then you should strongly consider a record.
π C# 9 also brings us "enhanced pattern matching" which is a fancy phrase for "one step closer to Perl". That's great for me since I love perl, but can you imagine trying to debug this?
public static bool IsLetterOrSeparator(this char c) => c is (>= 'a' and <= 'z') or (>= 'A' and <= 'Z') or '.' or ',';π C# 9 also allows you to omit the declaration of the type when constructing a new object Was typing really that hard? In an ideal world where people wrote maintainable code by default this is a nice change; but here in the real world I can already imagine the stuff we're going to see five years from now with this change.
private List _observations = new(); var forecast = station.ForecastFor(DateTime.Now.AddDays(2), new()); WeatherStation station = new() { Location = "Seattle, WA" };Your choice is to now either be var based or this new-fangled (sorry) new() based. We did not need another programming holy war, but it appears we're going to get it.
There are more C# 9 changes; but those are the highlights.
π The hipster's C# has also gotten updates -- F# 5 is now generally available. The blog post says there are several updates, but it appears like "Several" is doing a lot of heavy lifting in that sentence. That I can see there are two updates: String Interpolation and Typed Interpolation. Hooray?
π’ Visual Basic for .NET 5 has been released. There are no new updates (and no more language updates are planned), but VB.NET will support the project types that C# supports. Look at the flowers, VB.
π’ .NET 5 supports Web Assembly through Client-side Blazor, and Blazor has gotten several improvements. This is cool, but the target isn't people who are using JavaScript... It's... Webforms? Microsoft, among others, has tried several times to knock JavaScript off of its throne was the go-to language for Rich Internet Applications, and it hasn't worked yet -- but the Webforms folks need a new approach, and Blazor provides that.
π’ EF Core 5 for .NET 5 has been released I can't make it through the 81+ features they've added since 3.1 without worrying for the health of the EF team, but I'll at least try to hum a few bars: Many to Many relationships, EF Core CLI, ChangeTracker.Clear, Improved Code First Scaffolding, and more. Yes, and more.
π’ .NET Core 3.1.10 has been released. This is a bugfix release; centered mostly on EF Core 3.1 and ASP.NET Core.
π’ Microsoft.Data.Sqlite 5.0 has been released. Some nice goodies here if you use Sqlite; so enjoy.
π Ten ways your data project is going to fail to which I reply -- only 10? That's a much more manageable number than usual.
π Everything you wanted to know about Nuget Package versioning Look this stuff is not fun to read about; but sooner or later you or someone you love will spend a few days mired in package versioning hell, so bookmark this for that eventuality.
π Dave Brock shows you how to update the tag with Blazor. If you adopt blazor you now get to learn new ways of doing those things you already knew how to do in JavaScript. Weeeee.
π° Mads Torgerson talks about why C# is popular and where it's going from here C# is popular with businesses and its leg up on JavaScript is that it's stable. If the JS folks ever figure that out, C# is in trouble, but we're not ready to have that discussion yet.
π .NET IoT Libraries documentation has been published. I like this as it makes low level programming approachable ...
π Not about .NET, but relevant to our interests: Pintrest Engineering talks about they decreased their build times by 99% by changing one lineΒ in their build process. If you use Git and you use Hosted CI, you're going to want to pay attention to this. Hell, even if you don't use Hosted CI, taking a look at what tricks may speed up your build time is always a good idea. This post also re-inforces that good API naming is a must. If you're a git expert, you probably know this trick, but for the rest of us, this stuff comes down to discoverability, and I'm not exaggerating when I say the git API is... opaque at best.
π You can now tell the HttpRepl where to find your OpenAPI files. If you use HttpRepl (Microsoft's command line version of cURL or Postman) you can now tell it where to find your swagger or other OpenAPI files. This is one of those "I really need to check out HttpRepl" moments. One of the problems with cURL and Postman have been the... well.. generic nature of the tool. Having a tool that is aware of the modern web application stack is helpful. Special thanks to Brady Gaster on Twitter (@bradygaster) for making me aware of this.
π₯ Progress Telerik is hosting a "The State of .NET" Webinar. This is clearly a cash grab for your email address to so that they have you on their sales lists, but regardless, it should be informative. Since I already have your email address, you can always wait for the podcast episode to drop where I cover everything that Microsoft released during .NET Conf.
π .NET Conf is November 10th - November 12th. If you're listening to the podcast version of this, that means it's tomorrow. I'll be live tweeting this from @gortok on twitter and I'll have a special wrapup afterwards on the podcast... like I just said above.
π Scott Hanselman talks about Path.DirectorySeparatorChar gotchas in .NET Core when moving from Windows to Linux This is an informative blog post on what can happen when you hardcode special characters in your application, and it is something that just about every production .NET Framework Application has hiding in it... somewhere. Stay Frosty.
π Not content to ruin everyone's day with the String.IndexOf linguistic comparison problems in .NET Core we talked about last week, Jimmy Bogard found that a target framework moniker of NET50 and NET5.0 both work in Visual Studio. Both work due to Nuget parsing rules, and it's going to be interesting to see if this causes a problem come .NET 10.
π₯ Progress Telerik also hosted a "Future of Desktop" webinar on .NET last week, and while I missed the announcement before it happened, the video is available to watch. If you write .NET Desktop applications, check it out.
π Are Records in C# 9 immutable by default Dave Brock asks this question and deep dives into the answer in his blog post: Short answer is, it depends, and somewhere a software architect is basking in the glow of that answer.
π TypeScript 4.1 RC1 is now available Because TypeScript doesn't support Semver, there are nearly always breaking changes in minor releases, and this one is no different. If you use TypeScript, it's healthy to be aware of these changes before they break your build because your package.json file wasn't pinned to the patch version for TypeScript.
And lastly,
π The EF Core folks aren't sleeping at all if this release changelog is any indication. EF Core 5.0 RC2 is out; and the list of changes is too long to mention here. It's entirely evident that someone said "Look, EF Core is coming on November 10th, so it'd better be ready". If you know an EF Core team member, slide them a gift card and a socially distanced hug.
Hey again, what a week. We had a blue moon, Halloween, and Daylight savings time end all one one night.
In case you're the voting type here in these United States, that's happening tomorrow, where the choices are between two old white guys. You would think we would have learned our lesson by now, but we have not.
But this is not last week in politics, this is last week in .NET, so let's get to it.
π .NET Conf is November 10th-12th. I'll be livetweeting as much as possible on twitter @gortok, and if somehow your working situation allows you to partake, you should. This is when .NET 5 will be released, and there should be lots of goodies -- especially Blazor.
π Last week I talked about a bug with regards to String.IndexOf Comparisons in .NET 5 and .NET Core 3.1; this turns out to be a major paradigm shift (not an actual 'bug'), and a lot of people (including me) were caught by surprise by it. If you do String.IndexOf comparisons for cross-platform data ingestion (for example, you ingest log files in Windows and log files on *nix based systems and potentially have mixed \r\n (windows newlines) with \n (linux new lines)), you're gonna run into this. There are other situations where you'll run into it as well; but this would be the most common in an ascii context. The non-bug bug here is that the behavior is different on Windows vs. Linux and the behavior itself has changed over the life of .NET Core on Windows; specifically when they decided to stop using NLS and start using ICU on Windows (Linux has always used ICU). There's a github thread with more detail, but bottom line: Be on the lookout for this when you ingest strings from external sources and are using String.IndexOf or String.Contains; and make sure you're using Ordinal Comparisons in these cases. Jimmy Bogard (the person who found this non-bug bug) also released a blog post about it; he breaks down what happens and why. Levi Broderick also opened a new github issue to game-plan the way forward so developers aren't caught by surprise with this change.
π Simon Cropp found an issue on twitter where if you use Process.WaitForExit and the Process.OutputDataReceived events, and running multiple processes, you can get empty or partial output data (from redirected Standard Out (STDOUT)).
This bug is from 2018, but is getting increased attention now that .NET 5 is almost at the finish line. It's not fixed, but here's to being aware of it.
π Have you heard of the Microsoft.dotnet-httprepl package? It's... well.. an HTTP REPL for .NET. It's brought to us by the folks at Microsoft and they had another release last week for 5.0.0-preview.20527.2 . It is in preview, but I'd expect it to be generally available when .NET 5 lands. If you want something like Postman for the command line, give this a try. I can hear the cURL folks screaming now.
π₯ There's an archived video stream that took place on 2 October 2020 that talked about performance improvements in .NET 5. This video clocks in at just under two hours, but if you're a performance wonk, this may be up your alley. Special thanks to Dee Dee Walsh on twitter (@ddskier) for making me aware of this.
π¦ On the subject of Twitter, David Fowler (@davidfowl) released screenshots on how in .NET 5 you can now break down where a network call took the most time in ASP.NET Core. This works for the HttpServer, HttpClient, DNS, and Sockets classes, and is pretty wild.
β RIP Flash. There's an update to Windows 10 that permanently removes Adobe Flash. Flash defined rich internet applications at one point in time, and while I'm sad to see it go; it was a relic of yesteryear. Though funny enough nothing has replaced it yet bit for bit. This update is KB4577586, and is 'optional', for now.
π’ The call for speakers for .NET OpenSource days 2020 is open. If you run or maintain an open source project on .NET, you should consider submitting a talk.
π’ .NET Framework October 2020 Cumulative Update Preview Update for Windows 10 version 2004 and Windows Server, version 2004 has been released. This release fixes an issue if you use Kazakh collation in SqlClient, and a regression issue with WPF where two HostVisual elements disconnect at the same time. A crash with WPF has been fixed, this having to do with typing into a textBox. Users tend to type a lot so I'm glad they fixed it.
β In the category of API design ideas, there's a blog post out on a 'new' way to do REST API versioning, and I'll let you read it. I, for one, have been a part of enough holy wars over HTTP and "REST" API Versioning that I'm perfectly happy never getting into another one. Since twitter comments are typically better than blog comments, you can see how everyone else feels about this by checking out the twitter thread
And that's what happened Last Week in .NET. I'm George Stocker, and I'll see you next week.
Mostly community goodies this week. No releases, but that's not surprising given the impending release on November 10th. Here's what I found last week in .NET:
π’ Github now supports code navigation for C# repositories. If you've ever used OpenGrok, you may have wonder why services like Github never provided navigation between references. Well now they do. This is a phenomenol offering from Github; having the ability to click on a reference for an object and go to that class definition is... long overdue.
π° Mads Torgerson, designer on the C# team, talks about where C# is going I love C#, and I love that it's touted as one of the most popular programming languages out there. But, let's be real here: It's popular days are still to come. For a long time it was "Windows only" and firmly sucking on the Microsoft Teat. It's still doing that, but now with a veneer of open source, and actual cross-platform compatibility. Let's not kid ourselves: C# was good for businesses, but now it's good for everyone. I just hope it isn't too late.
π Did you know you could add AssemblyInfo attributes dynamically using the AssemblyMetadataAttribute (whew!) ... attribute? This is from March 2018 so I'm sure the API has changed a little bit, but a tweet from James Newton-King alerted me to this feature in .NET Core. If you need to modify your AssemblyInfo.cs at build time, this provides a great way of doing that. At least until the Zoomers come and decide that version numbers are passe and we should just deal with CalVer instead. All hail the Zoomers. Also I'm watching way too much TikTok.
π¦ Speaking of TikTok, Microsoft is a little depressed that their acquisition of TikTok didn't pan out so they've been releasing "One Dev Question, One day" videos, and this week's ask "What is C#"? My go to answer of "A really fucking awesome programming language that is tainted by its association with Microsoft" was rejected, quite unfairly I might add.
π’ Microsoft Edge now supports Linux. In a "No really, we've changed" moment, Microsoft now supports Linux on Microsoft Edge. I don't have a snarky thing to say about this, except perhaps to question if their marketing department understands who their customer actually is. Hint: It's not people that use Linux on their desktop. I'd also like to add that the money they put towards the development of Edge on Linux, they could have very well paid off an Open Source author or two. You know, like the guy from Appget?
β³ In what we will all undoubtedly regret in 5 years, there's a new course out on how to do full stack development with Blazor and WebAssembly. This is of course a terrible idea, but my support goes out to the gentlemen who are profiting off the popularity of Blazor. I don't have a dog in this metaphorical fight, but anyone who has worked with ASP.NET webforms knows how this works out: JavaScript does it easier and better, and you end up maintaining something the community has shifted away from.
β Nuget.org has released a survey asking the community for its thoughts on Nuget. This survey closes soon, so take it now (I have no idea when it closes, but given that this is a weekly newsletter, we can safely assume it's not long for this world). Microsoft has long ignored Nuget, so please take the survey so its issuers can keep their jobs.
π€ There's a github issue open that addresses the "MyMeth" problem in .NET Docs In the .NET Docs, (bless their hearts) they had documentation that referred to a "method", and they called it "MyMeth" instead of "MyMethod". It was of course noted and brought up, and sadly for the Breaking Bad fans among us, is going to be fixed.
π Apparently OData is still alive In what I will consider a "Holy Shit" moment, apparently OData 8.0.0 preview has been released. If you haven't already jumped ship to GraphQL and still want a hella-insecure way to query your data, might I recommend OData?
π Choose a .NET Game Engine Microsoft is back on a "Tout C# for Game Development" kick and I am here for it. No, I do not forgive them for hurting XNA, but I'm going to give Microsoft their due Kudos: C# is viable to use for game programming, and they're doing their best to make sure everyone knows it. Special thanks to Abdullah Hamed for the tweet that made me aware of this series.
π The .NET team has released a site that shows their roadmap, pulled directly from their Github issues This is a good look into the Microsoft machine surrounding .NET, and well worth your time if you're interested in the future of .NET.
π Attribute-Based Access Control With Blazor WebAssembly and IdentityServer 4 In what I can only characterize as a bad idea icecream topped with terrible idea sprinkles, there's a series out on Codemaze on how to develop ABAC with Blazor WebAssembly. Personally, I'd be delighted to know if this fits a usecase you have and whether you're going to implement it. Also, please send me a 'before' email so after your project's launched we can commiserate over the idea and lost youth.
π Rick Strahl takes you into the process of creating .NET Custom project types with the .NET CLI Project Templates (whew!) Long story short, if you create microservices or otherwise want to enforce defaults and standards when creating a new project, this blog post is for you.
π Jimmy Bogard found a bug in the .NET Core runtime, where string indexOf comparison fails or breaks depending on which runtime you use. As it turns out, Microsoft switched to ICU instead of using NLS (what they were using previously), and this change has the side-effect of breaking string comparison code that doesn't specify a culture or StringComparison.Ordinal. Microsoft views this as the cost of doing business when they switched to ICU instead of NLS, which makes it not a bug, just a feature we didn't connect the dots on.
π Layla Porter, newly elected .NET Foundation Board Member, talks on .NET Rocks about... The .NET Foundation, specifically, it's goals and how it needs to evolve.
π Jon Skeet takes us through the .NET Functions Framework If you're trying to deve...
This is Last Week in .NET for the week that ended 17 October 2020. Lots of releases and CVE fixes last week, so let's get to it.
π’ .NET 5 RC2 has been released. I mentioned last week that RC 1 was probably the last RC until GA, and I was wrong. I won't pundit on that any more, I have, in fact, learned my lesson. ClickOnce makes an appearance, and there are several smaller updates in this release.
π’ .NET Core 3.1.9 has been released. This release includes bugfixes across the runtime, framework, and ASP.NET Core as well as support for Fedora 33 and Ubuntu 20.10
π’ .NET Core 2.1.23 has been released Much like its hotter younger brother 3.1.9, 2.1.23 has bugfixes and updates for the runtime as well as the same aforementioned support for new releases of Fedora and Ubuntu.
π’ WinRT 0.8 has been released This has to do with using C# with WinRT, and at this point with the number of fluctuations to the Windows UI story, I'm not sure what the hell this does or who's it for.
π¨ https://www.bleepingcomputer.com/news/security/microsoft-october-2020-patch-tuesday-fixes-87-security-bugs/ That's a lot. So much so that the list of CVEs in this Patch Tuesday is itself too long to talk about.
The patches and CVE fixes cover the following software:
π¨ Microsoft also patched CVE-2020-16898, which allowed someone to use a malformed IPV6 ICMP Packet to... take over a system?!?!?!
βοΈ .NET Foundation September/October 2020 update [https://dotnetfoundation.org/blog/2020/10/14/blog/posts/net-foundation-september-october-2020-update](.NET Foundation join's OSI's affiliate initiative; new .NET projects are showcased)
π₯ Microsoft releases .NET Live TV! (Not to be confused with Microsoft's "Live" product). The goal is to have "Netflix for .NET" There's a lot of production to put into a 'live' TV channel, and if anyone can do it, Microsoft can. I just wish they'd use that money to pay the OSS maintainers whose projects they copy.
π₯ Speaking of Microsoft Live TV. Channel 9 released another video in a series of Progressive Web Applications with Blazor π¦ Part of the release for .NET 5 RC2 is the ability to use ClickOnce deployment with .NET 5. As the tweet says, "This is huge" and I'm only hoping it works out better this time. In the teams I've been a part of, there was always a reason why ClickOnce wouldn't work; but maybe that's all been fixed? π₯ How does .NET 5 change my development? Immo Landwerth of the .NET team takes the time to answer that question in a whole minute and 25 seconds. Just a little more shaving and you can get it into a TikTok. Brb, starting a tiktok for .NET.
π₯ Immo Landwerth takes you through how .NET 5's compatibility analyzer works when trying to work with cross platform code. If you get "PlatformNotSupported" Exceptions, this video is for you.
π¨: Microsoft republished a fix for CVE-2020-1147 because it was breaking SQL CLR objects. They didn't find it sooner because there are about five people in the known universe that use SQL CLR Objects. Thoughts and Prayers.
π°: Octopus Deploy is now a corporate sponsor for the .NET Foundation. This is a big change from 8 months ago when Octopus Deploy cut ties with Microsoft, and both blog posts are by the same person, Paul Stovall, Founder of Octopus Deploy.
In the post, Paul details that they want to help change the trajectory of .NET Open Source by funding it, and for that I commend them. It seems like they want to try to 'change things from the inside', and maybe they'll be able to. Regardless, thank you, Paul, and thank you Octopus Deploy.
π¦ Kevin Jones (aka @vcsjones on Twitter) showed an open issue in .NET where misusing stackalloc for a dynamically bounded array could cause a Stack Overflow in .NET. This is fixed in the "master" branch for the .NET Repo (can we get a branch name change, Microsoft), and maybe we'll see a .NET 5 RC3 or maybe this will just be in the GA version.
π Karen Payne released a blog post on how to work with Delegates and Events in VB.NET. It's wonderful to see people blog about VB.NET, and we need more of that. It's a wonderful language in its own right. Thanks, Karen.
π .NET Conf (yes, the correctly spelled one) is November 10th-12th) Are you 'going'? If not, I'll be livetweeting it @gortok on twitter. You know where the mute button is.
It was a pretty busy week for the world of .NET. I'm George Stocker, and I help teams write .NET systems that are easy to maintain and improve. If you're interested in learning more, check out www.doubleyourproductivity.io.
From the publisher's feed