Skip to content

fix(security): stopped the test restore from fetching SqlClient 4.7.0 - #167

Merged
karlspace merged 1 commit into
mainfrom
fix/security-sqlclient-test-restore
Oct 10, 2026
Merged

karlspace merged 1 commit into
mainfrom
fix/security-sqlclient-test-restore

Conversation

@karlspace

@karlspace karlspace commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Closes the open Dependabot alerts on System.Data.SqlClient 4.7.0 (2 high, 2 moderate). The library packages do not change. The fix is in the test project only.

Alert Advisory Severity Manifest
#4 GHSA-98g6-xh36-x2p7 (CVE-2024-0056) high Packages/system.data.sqlclient/4.7.0/system.data.sqlclient.4.7.0.nupkg
#6 GHSA-98g6-xh36-x2p7 (CVE-2024-0056) high Packages/system.data.sqlclient/4.7.0/system.data.sqlclient.nuspec
#3 GHSA-8g2p-5pqh-5jmc (CVE-2022-41064) moderate ...4.7.0.nupkg
#5 GHSA-8g2p-5pqh-5jmc (CVE-2022-41064) moderate ...nuspec

Why the alerts were still open after 9b620a0

  • nuget.config sets globalPackagesFolder to ./Packages. The automatic dependency submission (submit-nuget, component-detection with the NuGet detector) scans every .nupkg and .nuspec in that folder. It reports every package that was downloaded, including ones the build never resolves.
  • 9b620a0 added a direct reference to System.Data.SqlClient 4.9.1 in Desktop.Reporting. That fixed the resolved graph: 4.9.1 wins and NuGetAudit raises no NU1903.
  • BAUERGROUP.Shared.Test reaches Stimulsoft through its ProjectReference to Desktop.Reporting. NuGet's resolver (DependencyGraphResolver) skips a transitive dependency before fetching it only when the project being restored references that package directly. A direct reference inside a ProjectReference does not count. So the test restore still downloaded 4.7.0, which Stimulsoft.Reports.Engine 2022.1.2 requests. NuGet then rejected 4.7.0, but the file stayed in ./Packages.
  • Evidence from the CI restore log of run 37184021260 (PR deps(dotnet): Bump Sentry and Sentry.NLog #166):
    • At 06:51:53 there is GET https://api.nuget.org/v3-flatcontainer/system.data.sqlclient/4.7.0/system.data.sqlclient.4.7.0.nupkg.
    • At that moment only Data, Cloud, Avalonia.Test and Shared.Test were being restored.
    • Desktop.Reporting only started restoring at 06:51:58.

Change

  • tests/BAUERGROUP.Shared.Test: added a direct PackageReference to System.Data.SqlClient, using the central version 4.9.1, with a comment explaining why. The test project is IsPackable=false, so no published nupkg changes.
  • Directory.Packages.props: updated the comment on the existing central version. The version did not change.

Verification (CI)

  • Build & Test passed on Windows (run 38010454481): 574 + 46 tests passed. Build & Test (Linux, Avalonia) passed: 46 tests. Validate Package (Build & Pack), CodeQL and GitGuardian passed too.
  • The CI restore log has 0 requests for system.data.sqlclient/4.7.0 (on deps(dotnet): Bump Sentry and Sentry.NLog #166 it had 2) and still 2 for 4.9.1. There are no NU19xx audit warnings.
  • The dependency review (dependency-graph/compare from main to this branch, after submit-nuget run 38010424596) shows two removals: System.Data.SqlClient 4.7.0 in Packages/system.data.sqlclient/4.7.0/system.data.sqlclient.4.7.0.nupkg and in .../system.data.sqlclient.nuspec. The only addition is the static csproj entry, which has no vulnerabilities. The NuGet detector component count went from 175 to 174.

After merge, the next submit-nuget run on main submits a snapshot without the 4.7.0 manifests. Dependabot should then close #3 to #6 as fixed.

The direct System.Data.SqlClient 4.9.1 reference in Desktop.Reporting
(9b620a0) fixed the resolved graph, but Dependabot alerts #3-#6 stayed
open. nuget.config puts the global packages folder at ./Packages, and
automatic dependency submission scans every nupkg/nuspec in it.

Restoring the test project still downloaded 4.7.0 into ./Packages
(CI restore log: GET .../system.data.sqlclient/4.7.0/...nupkg). The
NuGet resolver only skips a transitive dependency before fetching it
when the restored project itself references it directly; a direct
reference inside a ProjectReference does not count. 4.9.1 still won
resolution, so no build ever used 4.7.0 (no NU1903 warning).

* BAUERGROUP.Shared.Test references System.Data.SqlClient directly
  (central version 4.9.1), so Stimulsoft's request for 4.7.0 is
  skipped and never downloaded
* Test project only (IsPackable=false): no published package changes

Advisories (System.Data.SqlClient 4.7.0 -> 4.9.1 in ./Packages):
* GHSA-98g6-xh36-x2p7 (CVE-2024-0056, high) - alerts #4, #6
* GHSA-8g2p-5pqh-5jmc (CVE-2022-41064, moderate) - alerts #3, #5
@karlspace
karlspace merged commit 9a41299 into main Oct 10, 2026
17 checks passed
@karlspace
karlspace deleted the fix/security-sqlclient-test-restore branch October 10, 2026 09:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant