Skip to content

fix(build): Bump Microsoft.AspNetCore.OpenApi to 10.0.12 - #166

Merged
bitbiter-dev merged 1 commit into
masterfrom
fix/164-openapi-advisory
Sep 18, 2026
Merged

bitbiter-dev merged 1 commit into
masterfrom
fix/164-openapi-advisory

Conversation

@bitbiter-dev

Copy link
Copy Markdown
Owner

Summary

master currently does not build. Restore fails with NU1903 because the transitive Microsoft.OpenApi 2.0.0 carries a high-severity advisory (GHSA-v5pm-xwqc-g5wc), affecting Anichron.API and Anichron.API.Tests.Unit.

Directory.Build.props sets NuGetAudit=true, NuGetAuditLevel=moderate, NuGetAuditMode=all and TreatWarningsAsErrors=true, so a transitive advisory is correctly promoted to a build error. The audit configuration is working as designed — the dependency was simply stale. This blocked every PR, including #157.

Change

Microsoft.OpenApi is not pinned directly, so bumping the direct dependency pulls a patched version:

-    <PackageVersion Include="Microsoft.AspNetCore.OpenApi" Version="10.0.7" />
+    <PackageVersion Include="Microsoft.AspNetCore.OpenApi" Version="10.0.12" />

Deliberately minimal — one line. Several other packages remain on 10.0.7, but none of them trip the audit at moderate, so no further bumps are needed to restore a green build.

Test plan

  • dotnet build src/Anichron.slnx — Build succeeded, 0 warnings, 0 errors (fails on master without this change)
  • dotnet test src/Anichron.slnx — 596 passed, 0 failed (API 325, Worker 198, Core 47, Infrastructure 26)
  • dotnet format src/ --verify-no-changes — no diff

Note on why this went unnoticed

.github/dependabot.yml ignores version-update:semver-patch for dependency-name: "*" in the nuget ecosystem. 10.0.7 → 10.0.12 is a patch bump, and Dependabot ignore conditions suppress security updates as well as version updates — so this was never surfaced as a PR. Worth addressing separately so the next transitive advisory doesn't break the build the same silent way; captured in #164.

Closes #164

🤖 Generated with Claude Code

Restore failed on master with NU1903: the transitive Microsoft.OpenApi
2.0.0 carries a high severity advisory (GHSA-v5pm-xwqc-g5wc). Because
Directory.Build.props sets NuGetAuditMode=all with NuGetAuditLevel=moderate
and TreatWarningsAsErrors, the advisory is promoted to a build error and
blocks every PR, not just one.

Microsoft.OpenApi is not pinned directly; bumping the AspNetCore.OpenApi
direct dependency pulls a patched version. No other pinned package trips
the audit at moderate.

Closes #164

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@bitbiter-dev
bitbiter-dev merged commit cc805e7 into master Sep 18, 2026
6 checks passed
@bitbiter-dev
bitbiter-dev deleted the fix/164-openapi-advisory branch September 18, 2026 12:26
@bitbiter-dev

Copy link
Copy Markdown
Owner Author

Correction to this PR's description

The "Note on why this went unnoticed" section in the description above is wrong and is retracted. The fix itself (the version bump) is unaffected and correct.

What the description claimed: that .github/dependabot.yml's ignore block suppressed a Dependabot security update, because ignore conditions apply to security updates as well as version updates.

Why that's wrong: per GitHub's documentation, update-types only affects version updates, not security updates. A version-update:semver-patch ignore cannot suppress a security PR.

The actual mechanism: this repo has no packages.lock.json and does not set RestorePackagesWithLockFile. GitHub's dependency graph derives transitive NuGet dependencies from lock files, so without one it only sees direct PackageVersion entries. Verified against the repo's own SBOM:

  • Microsoft.AspNetCore.OpenApi — present (direct)
  • Microsoft.OpenApi — absent (transitive)
  • ~28 packages total, exactly the direct set

So the vulnerable package was invisible to Dependabot entirely. No ignore configuration would have changed that. The only thing in this repo that could detect a transitive advisory is NuGetAuditMode=all at restore time — which only fires when someone builds, and surfaces the problem by breaking the build rather than notifying anyone.

The ignore block is still worth revisiting, but for a different reason: it suppresses patch version updates for every dependency, which is why 10.0.7 was never offered as a routine bump. That's tracked separately.

Full corrected analysis in #164.

🤖 Generated with Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(build): Transitive Microsoft.OpenApi 2.0.0 advisory breaks restore on master

1 participant