Resolve the SQLitePCLRaw advisory in the Sqlite auth templates - #525
Closed
danielchalmers wants to merge 1 commit into
Closed
danielchalmers wants to merge 1 commit into
danielchalmers wants to merge 1 commit into
Conversation
EF Core 10 still resolves SQLitePCLRaw 2.1.11, which GHSA-2m69-gcr7-jv3q flags as high severity. NU1903 is an error under /warnaserror, so every --auth Individual template that uses Sqlite fails to build. Reference SQLitePCLRaw.bundle_e_sqlite3 explicitly under the same condition as the Sqlite provider, which lifts lib, core and provider to 2.1.12. All seven Sqlite auth permutations now build clean, and dotnet list package --vulnerable reports nothing.
Member
Author
|
Closing this as an upstream issue. The vulnerable resolution comes from EF Core, which still pulls SQLitePCLRaw 2.1.11 as of 10.0.10. Pinning Waiting for that instead. The branch Holding #524 until then, since making the workflow able to fail while this is outstanding would leave |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Every
--auth Individualtemplate that uses Sqlite currently fails to build:EF Core 10 — including the current 10.0.10 — still resolves SQLitePCLRaw 2.1.11 transitively. The advisory covers
<= 2.1.11, andNU1903is an error under/warnaserror, so the build fails. Nobody has had to touch the templates for this to break; it appeared when the advisory was published.This is what #524 surfaced.
mudblazor-cinever reported it because the script did not stop on a failing build.Fix
Reference
SQLitePCLRaw.bundle_e_sqlite3explicitly, under the same condition as the Sqlite provider, so it applies only where Sqlite is actually used and not to the--use-local-db(SqlServer) variants.Referencing the bundle rather than
lib.e_sqlite3directly keeps the whole set on one version. After the change:The floating
2.*matches the existing style in this file (10.*,9.*,4.*) and picks up future 2.x fixes. The comment marks it for removal once EF Core resolves 2.1.12 or later on its own.Verified
All seven Sqlite auth permutations generated and built with
/warnaserror:InteractivityAuto_Auth,InteractivityNone_Auth,InteractivityServer_Auth,InteractivityWasm_AuthInteractivityAuto_Global_Auth,InteractivityServer_Global_Auth,InteractivityWasm_Global_AuthAll pass.
dotnet list package --vulnerable --include-transitivereports no vulnerable packages for the generated app or its.Clientproject.Merge order
This should go in before #524. Once this is merged, #524 makes the workflow able to fail and CI is genuinely green; merging #524 first would leave
devred until this lands.