Sign in

Paulo Morgado

@paulomorgado.net
195 followers 327 following 796 posts

Technical Lead Vision-Box. ex-Microsoft. MVPAward alumnus. Opinions are my own.

PostsRepliesMedia
Paulo Morgado @paulomorgado.net · 12h
dlvr.it
Aspire 13.6: persistent telemetry, Java, and Rust apps
Explore Aspire 13.6 dashboard run history, first-party Java and Rust hosting, portable volume paths, CLI workflows, deployment, and integration updates.
000
Paulo Morgado @paulomorgado.net · 12h
dlvr.it
Aspire 13.6: Your dashboard gets memory
Aspire 13.6 keeps dashboard telemetry across runs, opens container exec shells right in the dashboard, adds first-party Java and Rust hosting, introduces portable volume paths, and previews Azure Container Apps Sandboxes.
000
Paulo Morgado @paulomorgado.net · 22h
dlvr.it
WSL containers is now generally available
WSL is central to our commitment to making Windows the best place to build, run and manage Linux workloads. As AI, cloud-native development, containers, and open-source ecosystems continue to converge on Linux, more developers are choosing to perform
020
Paulo Morgado @paulomorgado.net · 22h
dlvr.it
WSLC Architecture deep dive
WSL containers is now generally available! Check out this blog post to learn more about this overall feature enabling seamless access to Linux containers
000
Paulo Morgado @paulomorgado.net · 22h
dlvr.it
Visual Studio September Update - Power Your Workflow with Your Model - Visual Studio Blog
Bring your own AI model with updates to BYOM, fix NuGet vulnerabilities from the Error List, explore pull requests with the Git agent, see which operand decides an if condition, and attach to Podman containers.
000
Paulo Morgado @paulomorgado.net · 22h
dlvr.it
The hidden trap of fixed buffers in C#
After all, if they’re marked as unsafe, there’s gotta be a reason, right?
000
Paulo Morgado @paulomorgado.net · 23h
dlvr.it
Duende Software
Duende Software is a company that builds industry-leading security software.
001
Paulo Morgado @paulomorgado.net · 28/09/2026
dlvr.it
Laurent Kempé - C# 15 Collection Expression Arguments: What's New vs C# 12 and 13
C# 15 brings a focused upgrade to collection expressions: collection expression arguments via a leading with(...) element. If you're already using C# 12 coll...
000
Paulo Morgado @paulomorgado.net · 27/09/2026
dlvr.it
Changes to Microsoft Learn’s public documentation repositories | Microsoft Community Hub
Microsoft Learn is changing how it manages public documentation repositories. Learn what the changes mean for GitHub contributors and where to continue...
000
Paulo Morgado @paulomorgado.net · 23/09/2026
dlvr.it
Hot Exit in Visual Studio
Hot Exit. It sounds like what you do when the fire alarm goes off. Or like Visual Studio leaving the room in a hurry. It's neither. Hot Ex...
000
Paulo Morgado @paulomorgado.net · 22/09/2026
dlvr.it
Today I will... debug a production crash - Visual Studio Blog
Learn effective debugging techniques for C# applications and how to tackle performance issues with memory dumps.
010
Paulo Morgado @paulomorgado.net · 22/09/2026
dlvr.it
Creating a memory dump in C#
Learn how to create a memory dump in C# to capture the state of your application for debugging purposes.
000
Paulo Morgado @paulomorgado.net · 22/09/2026
dlvr.it
Experimental support for Device Bound Session Credentials (DBSC) in ASP.NET Core: Exploring the .NET 11 preview - Part 8
In this post I look at the new experimental support for DBSC provided by the Microsoft.AspNetCore.Authentication.DeviceBoundSessions package
000
Paulo Morgado @paulomorgado.net · 18/09/2026
dlvr.it
Dual-exporting .NET metrics with OTLP and Prometheus
Many applications export their metrics directly to Prometheus. If you’re unfamiliar with Prometheus, in a nutshell it’s a time-series database for storing metrics, like counters and histograms. Applications that store their metrics in Prometheus typically use a popular Prometheus client as part of the integration. Now that OpenTelemetry is a graduated CNCF project, many companies are now increasingly looking to move to OpenTelemetry to add more signals beyond metrics to their observability architecture. Logs and traces are popular additions for getting further insight into how applications behave. Profiles are also starting to become a popular fourth telemetry signal for even deeper understanding.
001
Paulo Morgado @paulomorgado.net · 16/09/2026
dlvr.it
Cake - Cake v6.3.0 released
Version 6.3.0 of Cake has been released. Take it for a spin and give us feedback on our discussion board. This release includes new features, improvements and bug fixes to Cake Scripting, Cake Frosting and Cake Sdk since the Cake v6.2.0 release! 🚀 🍰 Highlights of this release GitHub Actions OIDC trusted publishing — The new NuGetLogin command exchanges a GitHub Actions OIDC token for a short-lived NuGet.org API key, so publishing no longer needs a long-lived secret. Improved nullability support — Aliases generated from nullable-enabled addins keep their annotations, so #nullable addins no longer cause CS8632 warnings in Cake scripts or generated Cake.Sdk code. Improved report rendering — The task summary table no longer assumes a dark terminal background, so it stays readable in light themes. Typed dotnet tool aliases — DotNetToolInstall, DotNetToolRestore, DotNetToolRun, DotNetToolList, DotNetToolSearch, DotNetToolUpdate, DotNetToolUninstall, and DotNetToolExecute. Verbosity via configuration — Set verbosity in cake.config or CAKE_SETTINGS_VERBOSITY; the --verbosity argument still takes precedence. Also supported by the Cake.Sdk generator. Global exception handling in Cake.Sdk — Generated scripts catch unhandled exceptions, condense the output, and exit with a non-zero code without any manual setup. Build provider improvements — GitHub Actions exposes the remaining default environment variables (workflow TriggeringActor, WorkflowRef, RepositoryId, and runner Environment / IsDebug, among others), and Azure Pipelines gained the ##[command] formatting command. Tool & nested build fixes — InnoSetup locates Inno Setup 7, and CakeExecuteScript / CakeExecuteExpression now honour HandleExitCode, NoWorkingDirectory, PostAction, and SetupProcessSettings when running on Cake.Tool. Dependency and SDK updates GitHub Actions NuGetLogin for OIDC trusted publishing NuGet.org trusted publishing lets you exchange a GitHub Actions OIDC identity token for a short-lived API key, which means you no longer need to store a long-lived NUGET_API_KEY secret in your repository. Cake 6.3.0 adds NuGetLogin (#4945) so you can do that exchange from within your Cake script, without adding a separate login action step to your workflow and passing the key back into the build: Task("Publish") .Does(async () => { var apiKey = await GitHubActions.Commands.NuGetLogin(EnvironmentVariable("NUGET_USERNAME")); var settings = new DotNetNuGetPushSettings { ApiKey = apiKey, Source = "https://api.nuget.org/v3/index.json" }; foreach (var package in GetFiles("./artifacts/*.nupkg")) { DotNetNuGetPush(package, settings); } }); The OIDC token and the returned API key are automatically registered as secrets, so they're masked in the build log. Your workflow needs the id-token: write permission for the token request to succeed: jobs: publish: runs-on: ubuntu-latest permissions: id-token: write steps: - uses: actions/checkout@v5 - name: Run Cake uses: cake-build/cake-action@v3 with: target: Publish env: NUGET_USERNAME: your-nuget-account If you publish to a different feed, the GitHubNuGetLoginSettings overload lets you override the token service URL and OIDC audience: var apiKey = await GitHubActions.Commands.NuGetLogin( new GitHubNuGetLoginSettings( UserName: "your-nuget-account", TokenServiceUrl: "https://www.nuget.org/api/v2/token", Audience: "https://www.nuget.org")); Improved nullability support Addins compiled with nullable reference types enabled used to produce CS8632 warnings ("the annotation for nullable reference types should only be used in code within a #nullable annotations context") because Cake generates the alias declarations above your script, in a compilation where annotations are disabled. Adding #nullable disable to your own script didn't help. Cake 6.3.0 makes alias generation nullability-aware (#4977) rather than suppressing the warning: Only aliases that actually carry a nullable annotation are wrapped in #nullable enable / #nullable restore, so the rest of your script keeps the context it has today. Annotations round-trip through generics and arrays, so IList<string?>, string?[]?, and Task<string?> are all generated correctly. Generic parameter constraints keep their nullability, with class? and notnull emitted where applicable, while unconstrained type parameters stay unannotated. The Cake.Sdk generator received the matching fix (#165), so nullable return types are retained in generated code and flow into your IDE's nullable analysis. Improved report and exception rendering The task summary table styled both foreground and background colors, which assumed a dark terminal and made the report hard to read — in some cases unreadable — in light themes and terminals with a custom background (#4870). The report now only sets foreground colors and lets your terminal's own background show through, so it looks right regardless of theme. Cake.Sdk scripts also got better exception reporting (#179). Generated code now registers handlers for unhandled and unobserved task exceptions during bootstrap, formats them with Spectre.Console instead of dumping a raw stack trace, and exits with a non-zero code on critical failures. Failures that previously crashed silently — or scrolled past as unreadable output — are now condensed into a readable report, and it works without any setup in your script. Contributors This release was made possible thanks to the Cake team and the contribution of these awesome members of the Cake community listed below: devlead patriksvensson paulomorgado peymanr34 perclausen gep13 Full details of everything that was included in this release can be seen below. Issues Cake As part of this release we had Cake 60 issues closed. Feature #4991 Add support for verbosity via configuration. #4945 Add GitHub Actions NuGetLogin for OIDC trusted publishing. #4890 Add typed Cake aliases for dotnet tool subcommands. Improvement #4979 Update Microsoft.IdentityModel.JsonWebTokens to 8.22.0. #4976 Update Microsoft.Extensions.DependencyInjection to 9.0.20 (net9.0) & 10.0.12 (net10.0). #4968 Update Microsoft.CodeAnalysis.CSharp.Scripting ro 5.9.0. #4966 Update Basic.Reference.Assemblies.* to 1.8.11. #4964 Update Autofac to 9.3.2. #4958 Update NuGet.* to 7.9.0. #4956 Update .NET SDK to 10.0.401. #4931 Update Spectre.Console to 0.57.2. #4929 Update System.Security.Cryptography.Pkcs to 9.0.18 (net9.0) & 10.0.10 (net10.0). #4925 Update Microsoft.CodeAnalysis.CSharp.Scripting to 5.6.0. #4923 Update Autofac to 9.3.1. #4921 Update Microsoft.Extensions.DependencyInjection to 9.0.18 (net9.0) & 10.0.10 (net10.0). #4919 Update Microsoft.IdentityModel.JsonWebTokens to 8.19.2. #4917 Update .NET SDK to 10.0.302. #4916 Add format command support to IAzurePipelinesCommands. #4909 Update Spectre.Console to 0.57.1. #4904 Update Basic.Reference.Assemblies.* to 1.8.9. #4902 Update Autofac to 9.3.0. #4900 Add support for Inno Setup 7. #4897 Update Autofac to 9.2.0. #4893 Update Spectre.Console to 0.57.0. #4891 Add missing GitHub Actions default environment variables to GitHubActions provider. #4888 Update System.Security.Cryptography.Pkcs to 9.0.17 (net9.0) & 10.0.9 (net10.0). #4882 Update Microsoft.Extensions.DependencyInjection to 9.0.17 (net9.0) & 10.0.9 (net10.0). #4876 Update Spectre.Console to 0.56.0. #4867 Update Microsoft.IdentityModel.JsonWebTokens to 8.19.1. Bug #4985 CakeExecuteScript/CakeExecuteExpression silently ignore several CakeSettings when running via Cake.Tool. #4977 CS8632 when Cake.Tool generates aliases from nullable-enabled addins. #4870 Report table rendering breaks in terminals without a black background. Generator As part of this release we had Generator 28 issues closed. Feature #197 Add support for verbosity via configuration. #179 Add built-in global exception handling to generated Cake scripts. Improvement #199 Update Cake.* to 6.3.0 #185 Update Microsoft.Extensions.DependencyInjection to 9.0.20 (net9.0) & 10.0.12 (net10.0). #181 Update .NET SDK to 10.0.401. #171 Update Microsoft.Extensions.DependencyInjection to 9.0.18 (net9.0) & 10.0.10 (net10.0). #167 Update .NET SDK to 10.0.302. #154 Update .NET SDK to 10.0.301. #142 Update Microsoft.Extensions.DependencyInjection to 9.0.17 (net9.0) & 10.0.9 (net10.0). Bug #165 Generator doesn't pick nullable return types it seems.
000
Paulo Morgado @paulomorgado.net · 16/09/2026
dlvr.it
Today I will... improve test coverage - Visual Studio Blog
Boost your application quality by learning how to analyze our test coverage and improve it using Visual Studio features.
000
Paulo Morgado @paulomorgado.net · 16/09/2026
dlvr.it
Protecting File Access in the wwwroot Folder in ASP.NET
ASP.NET Core treats files in wwwroot as public static content, but occasionally applications create files there that should only be available to authorized users. In this post I look at several ways to protect those files and show a small middleware solution that lets selectively access files easily.
000
Paulo Morgado @paulomorgado.net · 16/09/2026
dlvr.it
Understanding Device Bound Session Credentials (DBSC)
In this post I provide an introduction to Device Bound Session Credentials, I look at how DBSC protects against session hijacking, and how the protocol works
000
Paulo Morgado @paulomorgado.net · 16/09/2026
dlvr.it
Performance Improvements in .NET 11
Take a tour through hundreds of performance improvements in .NET 11.
000
Paulo Morgado @paulomorgado.net · 11/09/2026
dlvr.it
Use C# unions and closed hierarchies in ASP.NET Core
Learn how C# unions and closed hierarchies work with System.Text.Json across ASP.NET Core Minimal APIs, MVC, SignalR, Blazor, and OpenAPI.
000
Paulo Morgado @paulomorgado.net · 09/09/2026
dlvr.it
Announcing .NET 11 Release Candidate 1
.NET 11 Release Candidate 1 is available with improvements across libraries, runtime, SDK, MSBuild, NuGet, C#, F#, ASP.NET Core, .NET MAUI, and Windows Forms.
000
Paulo Morgado @paulomorgado.net · 09/09/2026
dlvr.it
.NET and .NET Framework September 2026 servicing releases updates
A recap of the latest servicing updates for .NET and .NET Framework for September 2026.
000
Paulo Morgado @paulomorgado.net · 08/09/2026
dlvr.it
Today I will... find hidden latency across a distributed .NET application - Visual Studio Blog
When a distributed application feels slow, the user sees one delay. The code behind that delay may run across a web frontend, backend services, databases,
010
Paulo Morgado @paulomorgado.net · 08/09/2026
dlvr.it
VeritasSoftware/LiveHealthChecks: Real-Time Api Health Check Monitoring
Real-Time Api Health Check Monitoring. Contribute to VeritasSoftware/LiveHealthChecks development by creating an account on GitHub.
000
Paulo Morgado @paulomorgado.net · 02/09/2026
dlvr.it
Monitoring GitHub Copilot usage with the Aspire Dashboard
When talking to developers I get wildly different opinions about how "good" GitHub Copilot actually was for them. Some love it, some find it...
000
Paulo Morgado @paulomorgado.net · 01/09/2026
dlvr.it
Building a Supply Chain Attack with .NET and NuGet | Maarten Balliauw {blog}
Every time npm has a supply chain incident, it’s tempting to think “haha, npm had yet another supply chain attack!” and feel safe in .NET land. But the tools to do the same thing in .NET, or at least similar things, are all there. Module initializers, source generators, MSBuild targets, startup hooks. A number of techniques exist to smuggle code into someone’s codebase, and most of them run before your application’s Main method is even called.
000
Paulo Morgado @paulomorgado.net · 01/09/2026
dlvr.it
The pain of serializing unions and closed class hierarchies with System.Text.Json: Exploring the .NET 11 preview - Part 7
In this post I discuss the System.Text.Json support for unions and closed hierarchies coming in .NET 11, the decisions made, and some of the sharp edges I hit
120
Paulo Morgado @paulomorgado.net · 29/08/2026
dlvr.it
High-Performance C♯ in Practice - Zero-Allocation Spans, Memory Safety, and .NET 10 Best Practices
Master high-performance C♯ programming in .NET 10 with zero-allocation spans, memory safety, SearchValues, and stack JIT optimizations.
020
Paulo Morgado @paulomorgado.net · 27/08/2026
dlvr.it
VSLive! @ Microsoft HQ: Developer Takeaways and Must-Watch Sessions - Visual Studio Blog
VSLive! @ Microsoft HQ 2026 was one of the most energizing VSLive! events I’ve attended. What stood out was the level of engagement over five days of
110
Paulo Morgado @paulomorgado.net · 27/08/2026
dlvr.it
How Uno Platform uses .NET, MCP, and AI to build high quality apps - .NET Blog
How Uno Platform built two Model Context Protocol servers in C# so AI agents can ground themselves in real documentation and then see and drive a running cross-platform .NET app.
000
Paulo Morgado @paulomorgado.net · 26/08/2026
dlvr.it
The Visual Studio Debugger Agentic Workflow Gets a Test-Driven Upgrade - Visual Studio Blog
A few months ago, we introduced a new guided agentic workflow in the Visual Studio Debugger Agent designed to help you move from a bug report to a Visual Studio Blog
110
Paulo Morgado @paulomorgado.net · 26/08/2026
dlvr.it
Visual Studio August Update — Work Smarter Across Models and Branches - Visual Studio Blog
Visual Studio August Update — Work Smarter Across Models and Branches
000
Paulo Morgado @paulomorgado.net · 26/08/2026
dlvr.it
.NET Conf 2026
.NET Conf returns November 10-12, 2026, with three days of sessions, community, and the launch of .NET 11.
110
Paulo Morgado @paulomorgado.net · 25/08/2026
dlvr.it
Finding the total number of processors on a machine with .NET
In this post I show how to find the total number of logical CPUs on a host (not just those available to a process); something that isn't exposed in modern .NET
000
Paulo Morgado @paulomorgado.net · 25/08/2026
dlvr.it
Unlocking the Power of AI for Every Developer in Visual Studio with Bring your Own Model - Visual Studio Blog
The best AI in Visual Studio is the AI you can bring with you. Developers don't work in a single-model world anymore. You might reach for one model for We're bringing Bring Your Own Model (BYOM) to Visual Studio so more developers can use AI with the models their teams prefer, whether through GitHub Copilot or their own model deployments.
000
Paulo Morgado @paulomorgado.net · 24/08/2026
dlvr.it
Limit what NuGet packages can do in your project - Gérald Barré
Learn how to use IncludeAssets and ExcludeAssets to block NuGet analyzers and MSBuild targets, and reduce package build-time risks.
010
Paulo Morgado @paulomorgado.net · 24/08/2026
dlvr.it
Explore new features available in C# 15 preview - .NET Blog
C# 15 ships with .NET 11. It adds union types, closed hierarchies, a preview of the updated unsafe model, and a few smaller changes that remove everyday ceremony.
000
Paulo Morgado @paulomorgado.net · 20/08/2026
dlvr.it
Parsing IP addresses in C# at crazy speeds
We are all familiar with IP addresses such as 192.168.0.1. They are typically written as four numbers in the range 0 to 255 inclusive, separated by dots. In C#, you can parse them with the standard library using IPAddress.TryParse. Pedantic people are quick to point out that IP addresses can take different forms: they can … Continue reading Parsing IP addresses in C# at crazy speeds
000
Paulo Morgado @paulomorgado.net · 18/08/2026
dlvr.it
Aspire 13.5: Fresh pixels and better workflows
Aspire 13.5 refreshes the dashboard and aspire.dev, expands the Interaction Service, adds cross-scope Azure references and Kubernetes persistent volumes, and brings live terminals into the AppHost.
000
Paulo Morgado @paulomorgado.net · 17/08/2026
dlvr.it
xUnit.v3 4.0.0 released
xUnit.v3 got a new major release. This blog post is more about the consequences of that for your local build and CI/CD pipelines than about the new features.
010
Paulo Morgado @paulomorgado.net · 17/08/2026
dlvr.it
Use Aspire to implement and deploy the BFF security architecture
This blog demonstrates how to use Aspire to set up a solution for developing and deploying an ASP.NET Core web application with Auth0 as the identity provider and a downstream API. The application …
000
Paulo Morgado @paulomorgado.net · 11/08/2026
dlvr.it
Today I will... manage Git Submodules without leaving the IDE - Visual Studio Blog
If you've worked with Git submodules for any length of time, you probably have a love-hate relationship with them. They're genuinely useful for pulling a
010
Paulo Morgado @paulomorgado.net · 11/08/2026
dlvr.it
Keyed Services (Named registrations) in .NET Service Provider | Maarten Balliauw {blog}
You have an IMessageSender interface, with two implementations: EmailMessageSender and SmsMessageSender. You register both, and now the question is which one gets injected into your OrderConfirmationService constructor. The answer, unhelpfully, is whichever was registered last. This may also introduce subtle, unexpected bugs when new services are registered.
010
Paulo Morgado @paulomorgado.net · 10/08/2026
dlvr.it
Implement BFF using Auth0, Angular and ASP.NET Core
This post should how to implement a web application which needs secure access and secure identities. The application uses Angular as the UI tech, ASP.NET Core as the backend tech and a backend for …
000
Paulo Morgado @paulomorgado.net · 09/08/2026
dlvr.it
Beyond Chat: live Speech-to-Text with Foundry Local and C#
Build a live speech-to-text app in C# with Foundry Local, a compact Nemotron model, and local model lifecycle management.
000
Paulo Morgado @paulomorgado.net · 06/08/2026
dlvr.it
Test reporting in Microsoft.Testing.Platform: from red build to root cause
Microsoft.Testing.Platform brings failures into GitHub Actions and Azure DevOps, uses pipeline history to separate regressions from flakes, and preserves usable reports when a test host crashes.
000
Paulo Morgado @paulomorgado.net · 05/08/2026
dlvr.it
ZeroGC: an allocate-only garbage collector for .NET | Konrad 'Dev Nerd' Kokosa
A custom CoreCLR GC that only ever allocates and never reclaims memory - the simplest possible baseline for writing a real one, and a fun toy for measuring how GC-bound your app really is.
000
Paulo Morgado @paulomorgado.net · 04/08/2026
dlvr.it
Automatic CSRF protection based on Fetch Metadata headers: Exploring the .NET 11 preview - Part 6
In this post I describe the new Cross-Site Request Forgery protection added to ASP.NET Core that uses Fetch Metadata HTTP headers instead of antiforgery tokens
000
Paulo Morgado @paulomorgado.net · 03/08/2026
dlvr.it
Group your Dependabot Updates
Over the last week Dependabot has had more burr than usual, including a bunch of GitHub workflow updates for CodeQL, but bang, failed workflow.
000
Paulo Morgado @paulomorgado.net · 03/08/2026
dlvr.it
Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime
NuGet API key durations will be reduced to 30 days starting August 17th. This change will significantly strengthen the integrity of the NuGet supply chain.
000