This release includes the following enhancements:
Release date: February 5, 2026
Support for .NET 10
Support for .NET 10 has been added. See Supported Frameworks.
Support for C# 14
dotTEST can now analyze code written in C# 14.
Support for IDEs
The following IDE is now supported:
- Visual Studio 2026
Updated Static Analysis Rules
The following rules have been updated:
Rule ID | Updates |
|---|---|
CS.EXCEPT.RETHROW | Support for Live Static Analysis has been added. |
Additional Updates
- The
.slnxsolution file format is now supported.
Resolved Bugs and FRs in 2025.3.1
Bug/FR ID | Description |
|---|---|
CVE-2026-22732 | Critical vulnerability resolved by updating to spring-security version 6.5.9 |
CVE-2026-33937 | Critical vulnerability resolved by updating to handlebars version 4.7.9 |
DT-24649 | Framework Version of Sample Project |
DT-24690 | DotTEST 2025.3 with VS 2026(18.2.1) analyzes all projects instead of selected one |
Resolved Bugs and FRs in 2025.3.2
Bug/FR ID | Description |
|---|---|
DT-24785 | Report cannot be generated via cmd with option -report when folder does not exist |
Resolved Bugs and FRs in 2025.3.4
Bug/FR ID | Description |
|---|---|
CVE-2026-29145 | Critical vulnerability resolved by updating to Tomcat version 10.1.54 |
Resolved Bugs and FRs in 2025.3.5
Bug/FR ID | Description |
|---|---|
GHSA-5m62-pw8w-7w9f, GHSA-h6fc-48rj-7qqh, GHSA-r29c-68gh-xp6x, CVE-2026-41284, GHSA-5mp6-jrq3-r938, GHSA-fv25-8xcx-gqjc, GHSA-gx5v-xp9w-j4cg | Critical vulnerability resolved by upgrading tomcat-embed-core to 10.1.56. |
CVE-2026-12143, GHSA-hmw2-7cc7-3qxx | Critical vulnerability resolved by upgrading form-data to 4.0.6. |
CVE-2026-54512, CVE-2026-54513, GHSA-j3rv-43j4-c7qm, GHSA-rmj7-2vxq-3g9f | Critical vulnerability resolved by upgrading jackson-databind to 2.21.4. |
CVE-2026-40973, CVE-2026-40975 | Critical vulnerability resolved by upgrading spring-boot to 3.5.15. |
CVE-2026-41848, CVE-2026-41842, CVE-2026-41850, CVE-2026-41851, CVE-2026-41842, CVE-2026-41838, GHSA-rc42-6c7j-7h5r | Critical vulnerability resolved by upgrading Spring to 6.2.19. |
CVE-2026-46681, GHSA-x7j8-49r8-mr43 | Critical vulnerability resolved by upgrading ts-utils to 0.14.0. |
CVE-2026-48801, GHSA-22p9-wv53-3rq4 | Critical vulnerability resolved by upgrading linkify-it to 5.0.0. |
| DT-24896 | Java SocketClient stopped working and exits with timeout after 1s with getsockopt error code |