Repository navigation
Refresh dependencies and fix vulnerable packages - #85
Merged
Merged
Conversation
Security: - SixLabors.ImageSharp 3.1.12 -> 4.1.2 in all three projects. Every advisory affecting 3.1.12 is patched only in 4.1.2 (major bump). Spectre.Console.ImageSharp 0.57.2 still declares a 3.1.12 dependency; the direct 4.1.2 reference takes precedence. CanvasImage rendering was verified against 4.1.2 with `images display`. - Microsoft.Data.Sqlite 10.0.8 -> 10.0.12 pulls SQLitePCLRaw 2.1.12, which fixes GHSA-2m69-gcr7-jv3q (<= 2.1.11). Non-breaking updates: - Dapper 2.1.66 -> 2.1.89 - Microsoft.Extensions.AI 10.6.0 -> 10.10.0 - Microsoft.Extensions.AI.OpenAI 10.6.0 -> 10.10.1 - Microsoft.Extensions.DependencyInjection / Hosting 10.0.8 -> 10.0.12 - OpenAI 2.10.0 -> 2.14.0 - System.CommandLine 2.0.8 -> 2.0.12 - System.Numerics.Tensors 10.0.8 -> 10.0.12 - Tests: coverlet.collector 10.1.0, FluentAssertions 8.11.0, Microsoft.NET.Test.Sdk 18.10.1, Moq 4.21.0 - Benchmarks: ImageSharp as above - Transitive pins (same-major): System.ClientModel 1.16.0, System.Memory.Data 10.0.12, Microsoft.Extensions.* 10.0.12 (tests and benchmarks) Version bumped to 7.2.1. Claude-Session: https://claude.ai/code/session_01HeT3cg5NLmfB7qeubjxDCr
Contributor
There was a problem hiding this comment.
- CI
build-and-testfailed, and.ci-review/ci-failures.mdcontains no log output, so I could not read the exact error. I could not run a local build either. The most likely cause is the SixLabors.ImageSharp bump from 3.1.12 to 4.1.2 inPixelbadger.Toolkit.csprojand in the Benchmarks project. That is a major-version upgrade, which conflicts with a dependency-refresh PR and with the "non-breaking (same-major)" comment. ImageSharp 4.x has API and licensing changes.Spectre.Console.ImageSharp0.57.2 is still pinned and probably targets ImageSharp 3.x. Fix: rundotnet buildanddotnet testlocally, fix the failure, and either revert ImageSharp to 3.1.x or migrate the steganography and display code and bumpSpectre.Console.ImageSharpto a compatible release. - A major ImageSharp upgrade is a breaking dependency change. The version bump to 7.2.1 is only a PATCH. Either drop the major bump or justify the version choice.
- The pinned "transitive" packages (
Microsoft.Extensions.*.Abstractions,System.ClientModel,System.Memory.Data) are added to three projects, including the Tests and Benchmarks projects. This may trigger NU1605 downgrade errors or version conflicts, and it creates maintenance burden. Remove them unless a vulnerability or conflict requires them, and say which one in the comments. - No tests were added or run to show that the steganography and display paths still work after the ImageSharp upgrade. Confirm that the existing image tests pass.
Automated review of 88e1675
ImageSharp 4.x requires a Six Labors license, which broke the build. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
LGTM. CI is green. ImageSharp is back on 3.1.12, the pinned transitive packages are gone, and the 7.2.1 patch bump now fits a same-major dependency refresh. Nit: the diff leaves a few stray blank lines in the csproj files.
Automated review of b8229f5
ImageSharp 4.x validates a Six Labors license at build time and fails Release builds without one. CI now writes the SIXLABORS_LICENSE secret to a runner temp file and points SixLaborsLicenseFile at it, in the PR build job and the NuGet publish build and publish jobs. The license file is gitignored so a local sixlabors.lic cannot be committed. Claude-Session: https://claude.ai/code/session_01HeT3cg5NLmfB7qeubjxDCr
Resolves b8229f5 by keeping the ImageSharp 4.1.2 upgrade and the same-major transitive pins. The Six Labors license is supplied to CI through the SIXLABORS_LICENSE secret. Claude-Session: https://claude.ai/code/session_01HeT3cg5NLmfB7qeubjxDCr
GitHub doesn't expose the runner context at job level, so the SixLaborsLicenseFile job env made the workflow fail before any job ran. Export the license path from the license step with GITHUB_ENV instead. Claude-Session: https://claude.ai/code/session_01HeT3cg5NLmfB7qeubjxDCr
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security:
advisory affecting 3.1.12 is patched only in 4.1.2 (major bump).
Spectre.Console.ImageSharp 0.57.2 still declares a 3.1.12 dependency;
the direct 4.1.2 reference takes precedence. CanvasImage rendering was
verified against 4.1.2 with
images display.which fixes GHSA-2m69-gcr7-jv3q (<= 2.1.11).
Non-breaking updates:
Microsoft.NET.Test.Sdk 18.10.1, Moq 4.21.0
System.Memory.Data 10.0.12, Microsoft.Extensions.* 10.0.12 (tests and
benchmarks)
Version bumped to 7.2.1.
Claude-Session: https://claude.ai/code/session_01HeT3cg5NLmfB7qeubjxDCr