Skip to content

chore(samples): drop the MessagePack pin from the AppHost - #228

Open
cosmin-staicu wants to merge 1 commit into
mainfrom
chore/drop-messagepack-pin
Open

cosmin-staicu wants to merge 1 commit into
mainfrom
chore/drop-messagepack-pin

Conversation

@cosmin-staicu

Copy link
Copy Markdown
Member

The AppHost referenced MessagePack directly only to force a patched version (GHSA-hv8m-jj95-wg3x) over the one Aspire brought in through StreamJsonRpc. The samples never use it.

StreamJsonRpc 2.25.29 (Aspire 13.x) now requires MessagePack ≥ 2.5.302, which includes the fix. Without the pin, restore resolves 2.5.302 and NuGet audit reports nothing.

  • Remove the PackageReference from the AppHost csproj
  • Remove the PackageVersion from Directory.Packages.props

dotnet build -c Release -warnaserror passes.

The pin forced a patched MessagePack (GHSA-hv8m-jj95-wg3x) past the
version Aspire pulled in through StreamJsonRpc. StreamJsonRpc 2.25.29
now requires MessagePack 2.5.302, which already carries the fix, and
restore reports no audit warnings without the pin.

Signed-off-by: Cosmin Staicu <cosmin.staicu@uipath.com>
@sonarqubecloud

sonarqubecloud Bot commented Oct 8, 2026

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant