Skip to content

Refresh dependencies and fix vulnerable packages - #85

Merged
pixelbadger merged 5 commits into
masterfrom
ccr-14f2c167-s4x98a
Oct 9, 2026
Merged

pixelbadger merged 5 commits into
masterfrom
ccr-14f2c167-s4x98a

Conversation

@pixelbadger

Copy link
Copy Markdown
Owner

Security:

  • SixLabors.ImageSharp 3.1.12 -> 4.1.2 in all three projects. Every
    advisory affecting 3.1.12 is patched only in 4.1.2 (major bump).
    Spectre.Console.ImageSharp 0.57.2 still declares a 3.1.12 dependency;
    the direct 4.1.2 reference takes precedence. CanvasImage rendering was
    verified against 4.1.2 with images display.
  • Microsoft.Data.Sqlite 10.0.8 -> 10.0.12 pulls SQLitePCLRaw 2.1.12,
    which fixes GHSA-2m69-gcr7-jv3q (<= 2.1.11).

Non-breaking updates:

  • Dapper 2.1.66 -> 2.1.89
  • Microsoft.Extensions.AI 10.6.0 -> 10.10.0
  • Microsoft.Extensions.AI.OpenAI 10.6.0 -> 10.10.1
  • Microsoft.Extensions.DependencyInjection / Hosting 10.0.8 -> 10.0.12
  • OpenAI 2.10.0 -> 2.14.0
  • System.CommandLine 2.0.8 -> 2.0.12
  • System.Numerics.Tensors 10.0.8 -> 10.0.12
  • Tests: coverlet.collector 10.1.0, FluentAssertions 8.11.0,
    Microsoft.NET.Test.Sdk 18.10.1, Moq 4.21.0
  • Benchmarks: ImageSharp as above
  • Transitive pins (same-major): System.ClientModel 1.16.0,
    System.Memory.Data 10.0.12, Microsoft.Extensions.* 10.0.12 (tests and
    benchmarks)

Version bumped to 7.2.1.

Claude-Session: https://claude.ai/code/session_01HeT3cg5NLmfB7qeubjxDCr

Security:
- SixLabors.ImageSharp 3.1.12 -> 4.1.2 in all three projects. Every
  advisory affecting 3.1.12 is patched only in 4.1.2 (major bump).
  Spectre.Console.ImageSharp 0.57.2 still declares a 3.1.12 dependency;
  the direct 4.1.2 reference takes precedence. CanvasImage rendering was
  verified against 4.1.2 with `images display`.
- Microsoft.Data.Sqlite 10.0.8 -> 10.0.12 pulls SQLitePCLRaw 2.1.12,
  which fixes GHSA-2m69-gcr7-jv3q (<= 2.1.11).

Non-breaking updates:
- Dapper 2.1.66 -> 2.1.89
- Microsoft.Extensions.AI 10.6.0 -> 10.10.0
- Microsoft.Extensions.AI.OpenAI 10.6.0 -> 10.10.1
- Microsoft.Extensions.DependencyInjection / Hosting 10.0.8 -> 10.0.12
- OpenAI 2.10.0 -> 2.14.0
- System.CommandLine 2.0.8 -> 2.0.12
- System.Numerics.Tensors 10.0.8 -> 10.0.12
- Tests: coverlet.collector 10.1.0, FluentAssertions 8.11.0,
  Microsoft.NET.Test.Sdk 18.10.1, Moq 4.21.0
- Benchmarks: ImageSharp as above
- Transitive pins (same-major): System.ClientModel 1.16.0,
  System.Memory.Data 10.0.12, Microsoft.Extensions.* 10.0.12 (tests and
  benchmarks)

Version bumped to 7.2.1.

Claude-Session: https://claude.ai/code/session_01HeT3cg5NLmfB7qeubjxDCr

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  1. CI build-and-test failed, and .ci-review/ci-failures.md contains no log output, so I could not read the exact error. I could not run a local build either. The most likely cause is the SixLabors.ImageSharp bump from 3.1.12 to 4.1.2 in Pixelbadger.Toolkit.csproj and in the Benchmarks project. That is a major-version upgrade, which conflicts with a dependency-refresh PR and with the "non-breaking (same-major)" comment. ImageSharp 4.x has API and licensing changes. Spectre.Console.ImageSharp 0.57.2 is still pinned and probably targets ImageSharp 3.x. Fix: run dotnet build and dotnet test locally, fix the failure, and either revert ImageSharp to 3.1.x or migrate the steganography and display code and bump Spectre.Console.ImageSharp to a compatible release.
  2. A major ImageSharp upgrade is a breaking dependency change. The version bump to 7.2.1 is only a PATCH. Either drop the major bump or justify the version choice.
  3. The pinned "transitive" packages (Microsoft.Extensions.*.Abstractions, System.ClientModel, System.Memory.Data) are added to three projects, including the Tests and Benchmarks projects. This may trigger NU1605 downgrade errors or version conflicts, and it creates maintenance burden. Remove them unless a vulnerability or conflict requires them, and say which one in the comments.
  4. No tests were added or run to show that the steganography and display paths still work after the ImageSharp upgrade. Confirm that the existing image tests pass.

Automated review of 88e1675

ImageSharp 4.x requires a Six Labors license, which broke the build.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. CI is green. ImageSharp is back on 3.1.12, the pinned transitive packages are gone, and the 7.2.1 patch bump now fits a same-major dependency refresh. Nit: the diff leaves a few stray blank lines in the csproj files.


Automated review of b8229f5

claude added 3 commits October 9, 2026 08:18
ImageSharp 4.x validates a Six Labors license at build time and fails
Release builds without one. CI now writes the SIXLABORS_LICENSE secret
to a runner temp file and points SixLaborsLicenseFile at it, in the
PR build job and the NuGet publish build and publish jobs.

The license file is gitignored so a local sixlabors.lic cannot be
committed.

Claude-Session: https://claude.ai/code/session_01HeT3cg5NLmfB7qeubjxDCr
Resolves b8229f5 by keeping the ImageSharp 4.1.2 upgrade and the
same-major transitive pins. The Six Labors license is supplied to CI
through the SIXLABORS_LICENSE secret.

Claude-Session: https://claude.ai/code/session_01HeT3cg5NLmfB7qeubjxDCr
GitHub doesn't expose the runner context at job level, so the
SixLaborsLicenseFile job env made the workflow fail before any job ran.
Export the license path from the license step with GITHUB_ENV instead.

Claude-Session: https://claude.ai/code/session_01HeT3cg5NLmfB7qeubjxDCr
@pixelbadger
pixelbadger merged commit 781b119 into master Oct 9, 2026
6 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants