fix(build): Bump Microsoft.AspNetCore.OpenApi to 10.0.12 - #166
Conversation
Restore failed on master with NU1903: the transitive Microsoft.OpenApi 2.0.0 carries a high severity advisory (GHSA-v5pm-xwqc-g5wc). Because Directory.Build.props sets NuGetAuditMode=all with NuGetAuditLevel=moderate and TreatWarningsAsErrors, the advisory is promoted to a build error and blocks every PR, not just one. Microsoft.OpenApi is not pinned directly; bumping the AspNetCore.OpenApi direct dependency pulls a patched version. No other pinned package trips the audit at moderate. Closes #164 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Correction to this PR's descriptionThe "Note on why this went unnoticed" section in the description above is wrong and is retracted. The fix itself (the version bump) is unaffected and correct. What the description claimed: that Why that's wrong: per GitHub's documentation, The actual mechanism: this repo has no
So the vulnerable package was invisible to Dependabot entirely. No The Full corrected analysis in #164. 🤖 Generated with Claude Code |
Summary
mastercurrently does not build. Restore fails withNU1903because the transitiveMicrosoft.OpenApi2.0.0 carries a high-severity advisory (GHSA-v5pm-xwqc-g5wc), affectingAnichron.APIandAnichron.API.Tests.Unit.Directory.Build.propssetsNuGetAudit=true,NuGetAuditLevel=moderate,NuGetAuditMode=allandTreatWarningsAsErrors=true, so a transitive advisory is correctly promoted to a build error. The audit configuration is working as designed — the dependency was simply stale. This blocked every PR, including #157.Change
Microsoft.OpenApiis not pinned directly, so bumping the direct dependency pulls a patched version:Deliberately minimal — one line. Several other packages remain on
10.0.7, but none of them trip the audit atmoderate, so no further bumps are needed to restore a green build.Test plan
dotnet build src/Anichron.slnx— Build succeeded, 0 warnings, 0 errors (fails onmasterwithout this change)dotnet test src/Anichron.slnx— 596 passed, 0 failed (API 325, Worker 198, Core 47, Infrastructure 26)dotnet format src/ --verify-no-changes— no diffNote on why this went unnoticed
.github/dependabot.ymlignoresversion-update:semver-patchfordependency-name: "*"in the nuget ecosystem.10.0.7 → 10.0.12is a patch bump, and Dependabot ignore conditions suppress security updates as well as version updates — so this was never surfaced as a PR. Worth addressing separately so the next transitive advisory doesn't break the build the same silent way; captured in #164.Closes #164
🤖 Generated with Claude Code