Skip to content

fix(build): Transitive Microsoft.OpenApi 2.0.0 advisory breaks restore on master #164

Description

@bitbiter-dev

Problem

master did not build. dotnet build src/Anichron.slnx failed at restore:

error NU1903: Warning As Error: Package 'Microsoft.OpenApi' 2.0.0 has a known high severity
vulnerability, https://github.com/advisories/GHSA-v5pm-xwqc-g5wc

It failed for Anichron.API and Anichron.API.Tests.Unit. Verified against 60bd66c in a clean worktree, with no local changes.

Microsoft.OpenApi is not pinned in src/Directory.Packages.props — it arrives transitively via Microsoft.AspNetCore.OpenApi 10.0.7. src/Directory.Build.props sets NuGetAudit=true, NuGetAuditLevel=moderate, NuGetAuditMode=all and TreatWarningsAsErrors=true, so a transitive advisory is correctly promoted to a build error. The audit config is working as designed; the dependency was simply stale.

This blocked every PR, not just one, including #157.

Fix

Bump the direct dependency so it pulls a patched Microsoft.OpenApi:

-    <PackageVersion Include="Microsoft.AspNetCore.OpenApi" Version="10.0.7" />
+    <PackageVersion Include="Microsoft.AspNetCore.OpenApi" Version="10.0.12" />

Verified: Build succeeded. 0 Warning(s), full suite 596 passed. No other package in the file trips the audit at moderate. Fixed in #166.

Root cause — corrected

Correction. An earlier revision of this issue claimed the cause was the ignore block in .github/dependabot.yml suppressing a Dependabot security update, on the reasoning that ignore conditions apply to security updates as well as version updates. That was wrong and is retracted. Per GitHub's own documentation, update-types only affects version updates, not security updates — so the blanket semver-patch ignore could not have suppressed a security PR. The corrected mechanism follows.

The real reason Dependabot never flagged this: the repo has no packages.lock.json, and RestorePackagesWithLockFile is not set anywhere.

GitHub's dependency graph for NuGet derives transitive dependencies from lock files. Without one, it only sees the direct PackageVersion entries in Directory.Packages.props. Confirmed empirically against the repo's own SBOM (GET /repos/bitbiter-dev/anichron/dependency-graph/sbom):

  • Microsoft.AspNetCore.OpenApi — present (direct)
  • Microsoft.OpenApi — absent (transitive)
  • ~28 NuGet packages total, i.e. exactly the direct set

So Microsoft.OpenApi was invisible to the dependency graph, and therefore to Dependabot alerts and Dependabot security updates. No configuration change to ignore would have surfaced it. The only mechanism in this repo capable of detecting a transitive advisory is NuGetAuditMode=all at restore — which fires only when someone builds, and reports it by breaking the build rather than by notifying anyone.

That is the actual gap: for a four-month idle period, nothing was watching.

Follow-ups (separate issues, not this one)

  1. Transitive blindness — enable RestorePackagesWithLockFile and commit packages.lock.json so transitive packages enter the dependency graph and Dependabot can see them. Needs a check on whether CI/Docker restores need --locked-mode handling.
  2. Patch drift — the ignore block does legitimately suppress patch version updates for every dependency (dependency-name: "*" + version-update:semver-patch). That is why 10.0.7 was never offered as a routine bump for four months. Real problem, just not a security-suppression one.
  3. Open question — confirm Dependabot alerts and Dependabot security updates are actually enabled on this repo. If they are off, item 1 buys nothing until they are on.

Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions