Sitelet https://github.com/fluentassertions/fluentassertions/pull/3283
Skip to content

Pin System.Security.Cryptography.Xml to patched version to fix build restore failures - #3283

Merged
dennisdoomen merged 1 commit into
mainfrom
dennisdoomen-fix-json-node-haveproperty-null
Jul 28, 2026
Merged

dennisdoomen merged 1 commit into
mainfrom
dennisdoomen-fix-json-node-haveproperty-null

Conversation

@dennisdoomen

Copy link
Copy Markdown
Member

Why

PR #3282's CI checks (and any other PR/branch right now) fail during dotnet restore of Build/_build.csproj, unrelated to any code changes:

error NU1903: Warning As Error: Package 'System.Security.Cryptography.Xml' 10.0.6
has a known high severity vulnerability, https://github.com/advisories/GHSA-23rf-6693-g89p
(+ 4 more advisories for the same package/version)

System.Security.Cryptography.Xml 10.0.6 is pulled in transitively by build-tooling packages referenced in Build/_build.csproj. Because Directory.Build.props sets TreatWarningsAsErrors = true, NuGet's audit warning (NU1903) is escalated to a hard error, breaking restore for the whole solution.

Fix

Add a direct PackageReference for System.Security.Cryptography.Xml pinned to the patched 10.0.10 version in Build/_build.csproj, overriding the vulnerable transitive version.

Verification

  • dotnet restore Build\_build.csproj — succeeds, no NU1903.
  • dotnet build Build\_build.csproj — succeeds, 0 warnings/errors.

Only touches build tooling; no public API or library changes, so no api-approved issue/docs update needed.

Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com

Build/_build.csproj transitively pulled in System.Security.Cryptography.Xml
10.0.6, which has several known high-severity DoS vulnerabilities. Since
Directory.Build.props sets TreatWarningsAsErrors, NuGet's audit warning
(NU1903) is escalated to a build error, breaking restore for the Build
project on every PR/branch (including #3282), unrelated to any code change.

Pin a direct PackageReference to the patched 10.0.10 version to override
the vulnerable transitive dependency.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings July 28, 2026 09:45

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes CI/restore failures caused by NuGet audit warnings (NU1903) being treated as errors during dotnet restore of the build tooling project (Build/_build.csproj). It does so by overriding a vulnerable transitive dependency with a patched direct reference, unblocking restore/build without affecting the library’s public API.

Changes:

  • Adds a direct PackageReference to System.Security.Cryptography.Xml pinned to 10.0.10 to override the vulnerable transitive 10.0.6.
  • Documents the reason for the pin (NU1903 / GHSA advisory) inline in the project file.

@dennisdoomen dennisdoomen changed the title Fix NU1903 restore error in Build tooling project Pin System.Security.Cryptography.Xml to patched version to fix build restore failures Jul 28, 2026
@github-actions

github-actions Bot commented Jul 28, 2026 •

Copy link
Copy Markdown

Test Results

    37 files  ±0      37 suites  ±0   2m 50s ⏱️ +14s
 6 388 tests ±0   6 387 ✅ ±0  1 💤 ±0  0 ❌ ±0 
39 674 runs  ±0  39 668 ✅ ±0  6 💤 ±0  0 ❌ ±0 

Results for commit 5b20d9b. ± Comparison against base commit 0cf3021.

This pull request removes 10 and adds 8 tests. Note that renamed tests count towards both.
FluentAssertions.Specs.Streams.StreamAssertionSpecs+HaveLength ‑ When_a_throwing_stream_should_have_a_length_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
FluentAssertions.Specs.Streams.StreamAssertionSpecs+HaveLength ‑ When_a_throwing_stream_should_have_a_length_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
FluentAssertions.Specs.Streams.StreamAssertionSpecs+HavePosition ‑ When_a_throwing_stream_should_have_a_position_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
FluentAssertions.Specs.Streams.StreamAssertionSpecs+HavePosition ‑ When_a_throwing_stream_should_have_a_position_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
FluentAssertions.Specs.Streams.StreamAssertionSpecs+NotHaveLength ‑ When_a_throwing_stream_should_not_have_a_length_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
FluentAssertions.Specs.Streams.StreamAssertionSpecs+NotHaveLength ‑ When_a_throwing_stream_should_not_have_a_length_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
FluentAssertions.Specs.Streams.StreamAssertionSpecs+NotHavePosition ‑ When_a_throwing_stream_should_not_have_a_position_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
FluentAssertions.Specs.Streams.StreamAssertionSpecs+NotHavePosition ‑ When_a_throwing_stream_should_not_have_a_position_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
Object name: 'GetLengthExceptionMessage'.)
Object name: 'GetPositionExceptionMessage'.)
FluentAssertions.Specs.Streams.StreamAssertionSpecs+HaveLength ‑ When_a_throwing_stream_should_have_a_length_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
Object name: 'GetLengthExceptionMessage'.)
FluentAssertions.Specs.Streams.StreamAssertionSpecs+HaveLength ‑ When_a_throwing_stream_should_have_a_length_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
Object name: 'GetLengthExceptionMessage'.)
FluentAssertions.Specs.Streams.StreamAssertionSpecs+HavePosition ‑ When_a_throwing_stream_should_have_a_position_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
Object name: 'GetPositionExceptionMessage'.)
FluentAssertions.Specs.Streams.StreamAssertionSpecs+HavePosition ‑ When_a_throwing_stream_should_have_a_position_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
Object name: 'GetPositionExceptionMessage'.)
FluentAssertions.Specs.Streams.StreamAssertionSpecs+NotHaveLength ‑ When_a_throwing_stream_should_not_have_a_length_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
Object name: 'GetLengthExceptionMessage'.)
FluentAssertions.Specs.Streams.StreamAssertionSpecs+NotHaveLength ‑ When_a_throwing_stream_should_not_have_a_length_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
Object name: 'GetLengthExceptionMessage'.)
FluentAssertions.Specs.Streams.StreamAssertionSpecs+NotHavePosition ‑ When_a_throwing_stream_should_not_have_a_position_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
Object name: 'GetPositionExceptionMessage'.)
FluentAssertions.Specs.Streams.StreamAssertionSpecs+NotHavePosition ‑ When_a_throwing_stream_should_not_have_a_position_it_should_fail(exception: System.ObjectDisposedException: Cannot access a disposed object.
Object name: 'GetPositionExceptionMessage'.)

♻️ This comment has been updated with latest results.

@coveralls

Copy link
Copy Markdown

Coverage Report for CI Build 30347946598

Coverage remained the same at 97.138%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 13403
Covered Lines: 13178
Line Coverage: 98.32%
Relevant Branches: 4384
Covered Branches: 4100
Branch Coverage: 93.52%
Branches in Coverage %: Yes
Coverage Strength: 80403.84 hits per line

💛 - Coveralls

@dennisdoomen
dennisdoomen requested a review from jnyrup July 28, 2026 10:01
@dennisdoomen dennisdoomen added the building Building and Infrastructure of Fluent Assertions label Jul 28, 2026
@dennisdoomen
dennisdoomen merged commit 8a7ddde into main Jul 28, 2026
14 checks passed
@dennisdoomen
dennisdoomen deleted the dennisdoomen-fix-json-node-haveproperty-null branch July 28, 2026 10:54
@github-actions

Copy link
Copy Markdown

Qodana for .NET

It seems all right 👌

No new problems were found according to the checks applied

💡 Qodana analysis was run in the pull request mode: only the changed files were checked
☁️ View the detailed Qodana report

Contact Qodana team

Contact us at qodana-support@jetbrains.com

This was referenced Oct 3, 2026

This branch was previously deployed

1 inactive deployment
qodana-pr — 5b20d9bd Deployed Jul 28, 2026 by dennisdoomen via Qodana Scan #27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

building Building and Infrastructure of Fluent Assertions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants