AI agents: use the documentation index at llms.txt to locate machine-readable pages. This section is indexed by https://docs.particular.net/nservicebus/llms.txt. The markdown version of this page is served as plain text. An MCP server at /mcp serves the same content via the search_docs and read_doc tools; it is read-only and needs no credentials. Markdown versions of documentation pages are available by appending .md to the page URL. Directory URLs use index.md. They are served as text/plain because some retrieval backends reject text/markdown.

Newtonsoft Serializer Upgrade Version 2 to 3

NewtonsoftSerializer obsolete

The NewtonsoftSerializer is obsolete in NServiceBus version 8. It uses TypeNameHandling.Auto as its default value which can be a security risk as it allows the message payload to control the deserialization target type. See CA2326: Do not use TypeNameHandling values other than None for further details on this vulnerability.

A new serializer NewtonsoftJsonSerializer has been introduced which uses TypeNameHandling.None as its default value.

Instead of:

var serialization = endpointConfiguration.UseSerialization<NewtonsoftSerializer>();

Use:

var serialization = endpointConfiguration.UseSerialization<NewtonsoftJsonSerializer>();

If TypeNameHandling.Auto is required, customize the instance of JsonSerializerSettings used for serialization. See the Json.Net Serializer documentation for more information.

Related Articles

  • Serialization
    .NET messaging systems require serialization and deserialization of objects sent/received over transports. NServiceBus achieves this using serializers.
  • Upgrade Version 7 to 8
    Instructions on how to upgrade NServiceBus from version 7 to version 8.