Skip to content

build: lift transitive SSH.NET above the GHSA-q939-rpr3-3284 vulnerable range - #1881

Merged
WhitWaldo merged 1 commit into
dapr:masterfrom
JoshVanL:pr/bump-sshnet-2026
Aug 14, 2026
Merged

WhitWaldo merged 1 commit into
dapr:masterfrom
JoshVanL:pr/bump-sshnet-2026

Conversation

@JoshVanL

Copy link
Copy Markdown
Contributor

Testcontainers 4.9.0 depends on SSH.NET 2025.1.0, which is inside the vulnerable range of GHSA-q939-rpr3-3284 (high severity, ScpClient recursive download arbitrary file write). NuGet audit promotes that to error NU1903, which currently fails every job in CI, on master and on every open PR, since the advisory published.

Pin SSH.NET 2026.0.0 (the first patched version) centrally and reference it directly from Dapr.Testcontainers so the transitive edge resolves above the vulnerable range. The pin can be dropped once Testcontainers ships a release depending on the patched line.

…le range

Testcontainers 4.9.0 depends on SSH.NET 2025.1.0, which is inside the
vulnerable range of GHSA-q939-rpr3-3284 (high severity, ScpClient
recursive download arbitrary file write). NuGet audit promotes that to
error NU1903, which currently fails every job in CI, on master and on
every open PR, since the advisory published.

Pin SSH.NET 2026.0.0 (the first patched version) centrally and
reference it directly from Dapr.Testcontainers so the transitive edge
resolves above the vulnerable range. The pin can be dropped once
Testcontainers ships a release depending on the patched line.

Signed-off-by: joshvanl <me@joshvanl.dev>
@JoshVanL
JoshVanL requested review from a team as code owners August 13, 2026 15:54

@WhitWaldo WhitWaldo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good - you beat me to publishing this by a day. Nice one!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants