Problem
master did not build. dotnet build src/Anichron.slnx failed at restore:
error NU1903: Warning As Error: Package 'Microsoft.OpenApi' 2.0.0 has a known high severity
vulnerability, https://github.com/advisories/GHSA-v5pm-xwqc-g5wc
It failed for Anichron.API and Anichron.API.Tests.Unit. Verified against 60bd66c in a clean worktree, with no local changes.
Microsoft.OpenApi is not pinned in src/Directory.Packages.props — it arrives transitively via Microsoft.AspNetCore.OpenApi 10.0.7. src/Directory.Build.props sets NuGetAudit=true, NuGetAuditLevel=moderate, NuGetAuditMode=all and TreatWarningsAsErrors=true, so a transitive advisory is correctly promoted to a build error. The audit config is working as designed; the dependency was simply stale.
This blocked every PR, not just one, including #157.
Fix
Bump the direct dependency so it pulls a patched Microsoft.OpenApi:
- <PackageVersion Include="Microsoft.AspNetCore.OpenApi" Version="10.0.7" />
+ <PackageVersion Include="Microsoft.AspNetCore.OpenApi" Version="10.0.12" />
Verified: Build succeeded. 0 Warning(s), full suite 596 passed. No other package in the file trips the audit at moderate. Fixed in #166.
Root cause — corrected
Correction. An earlier revision of this issue claimed the cause was the ignore block in .github/dependabot.yml suppressing a Dependabot security update, on the reasoning that ignore conditions apply to security updates as well as version updates. That was wrong and is retracted. Per GitHub's own documentation, update-types only affects version updates, not security updates — so the blanket semver-patch ignore could not have suppressed a security PR. The corrected mechanism follows.
The real reason Dependabot never flagged this: the repo has no packages.lock.json, and RestorePackagesWithLockFile is not set anywhere.
GitHub's dependency graph for NuGet derives transitive dependencies from lock files. Without one, it only sees the direct PackageVersion entries in Directory.Packages.props. Confirmed empirically against the repo's own SBOM (GET /repos/bitbiter-dev/anichron/dependency-graph/sbom):
Microsoft.AspNetCore.OpenApi — present (direct)
Microsoft.OpenApi — absent (transitive)
- ~28 NuGet packages total, i.e. exactly the direct set
So Microsoft.OpenApi was invisible to the dependency graph, and therefore to Dependabot alerts and Dependabot security updates. No configuration change to ignore would have surfaced it. The only mechanism in this repo capable of detecting a transitive advisory is NuGetAuditMode=all at restore — which fires only when someone builds, and reports it by breaking the build rather than by notifying anyone.
That is the actual gap: for a four-month idle period, nothing was watching.
Follow-ups (separate issues, not this one)
- Transitive blindness — enable
RestorePackagesWithLockFile and commit packages.lock.json so transitive packages enter the dependency graph and Dependabot can see them. Needs a check on whether CI/Docker restores need --locked-mode handling.
- Patch drift — the
ignore block does legitimately suppress patch version updates for every dependency (dependency-name: "*" + version-update:semver-patch). That is why 10.0.7 was never offered as a routine bump for four months. Real problem, just not a security-suppression one.
- Open question — confirm Dependabot alerts and Dependabot security updates are actually enabled on this repo. If they are off, item 1 buys nothing until they are on.
Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com
Problem
masterdid not build.dotnet build src/Anichron.slnxfailed at restore:It failed for
Anichron.APIandAnichron.API.Tests.Unit. Verified against60bd66cin a clean worktree, with no local changes.Microsoft.OpenApiis not pinned insrc/Directory.Packages.props— it arrives transitively viaMicrosoft.AspNetCore.OpenApi10.0.7.src/Directory.Build.propssetsNuGetAudit=true,NuGetAuditLevel=moderate,NuGetAuditMode=allandTreatWarningsAsErrors=true, so a transitive advisory is correctly promoted to a build error. The audit config is working as designed; the dependency was simply stale.This blocked every PR, not just one, including #157.
Fix
Bump the direct dependency so it pulls a patched
Microsoft.OpenApi:Verified:
Build succeeded. 0 Warning(s), full suite 596 passed. No other package in the file trips the audit atmoderate. Fixed in #166.Root cause — corrected
The real reason Dependabot never flagged this: the repo has no
packages.lock.json, andRestorePackagesWithLockFileis not set anywhere.GitHub's dependency graph for NuGet derives transitive dependencies from lock files. Without one, it only sees the direct
PackageVersionentries inDirectory.Packages.props. Confirmed empirically against the repo's own SBOM (GET /repos/bitbiter-dev/anichron/dependency-graph/sbom):Microsoft.AspNetCore.OpenApi— present (direct)Microsoft.OpenApi— absent (transitive)So
Microsoft.OpenApiwas invisible to the dependency graph, and therefore to Dependabot alerts and Dependabot security updates. No configuration change toignorewould have surfaced it. The only mechanism in this repo capable of detecting a transitive advisory isNuGetAuditMode=allat restore — which fires only when someone builds, and reports it by breaking the build rather than by notifying anyone.That is the actual gap: for a four-month idle period, nothing was watching.
Follow-ups (separate issues, not this one)
RestorePackagesWithLockFileand commitpackages.lock.jsonso transitive packages enter the dependency graph and Dependabot can see them. Needs a check on whether CI/Docker restores need--locked-modehandling.ignoreblock does legitimately suppress patch version updates for every dependency (dependency-name: "*"+version-update:semver-patch). That is why10.0.7was never offered as a routine bump for four months. Real problem, just not a security-suppression one.Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com