Pin System.Security.Cryptography.Xml to patched version to fix build restore failures - #3283
Conversation
Build/_build.csproj transitively pulled in System.Security.Cryptography.Xml 10.0.6, which has several known high-severity DoS vulnerabilities. Since Directory.Build.props sets TreatWarningsAsErrors, NuGet's audit warning (NU1903) is escalated to a build error, breaking restore for the Build project on every PR/branch (including #3282), unrelated to any code change. Pin a direct PackageReference to the patched 10.0.10 version to override the vulnerable transitive dependency. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
This PR fixes CI/restore failures caused by NuGet audit warnings (NU1903) being treated as errors during dotnet restore of the build tooling project (Build/_build.csproj). It does so by overriding a vulnerable transitive dependency with a patched direct reference, unblocking restore/build without affecting the library’s public API.
Changes:
- Adds a direct
PackageReferencetoSystem.Security.Cryptography.Xmlpinned to10.0.10to override the vulnerable transitive10.0.6. - Documents the reason for the pin (NU1903 / GHSA advisory) inline in the project file.
Test Results 37 files ±0 37 suites ±0 2m 50s ⏱️ +14s Results for commit 5b20d9b. ± Comparison against base commit 0cf3021. This pull request removes 10 and adds 8 tests. Note that renamed tests count towards both.♻️ This comment has been updated with latest results. |
Coverage Report for CI Build 30347946598Coverage remained the same at 97.138%Details
Uncovered ChangesNo uncovered changes found. Coverage RegressionsNo coverage regressions found. Coverage Stats💛 - Coveralls |
Qodana for .NETIt seems all right 👌 No new problems were found according to the checks applied 💡 Qodana analysis was run in the pull request mode: only the changed files were checked Contact Qodana teamContact us at qodana-support@jetbrains.com
|
Why
PR #3282's CI checks (and any other PR/branch right now) fail during
dotnet restoreofBuild/_build.csproj, unrelated to any code changes:System.Security.Cryptography.Xml10.0.6 is pulled in transitively by build-tooling packages referenced inBuild/_build.csproj. BecauseDirectory.Build.propssetsTreatWarningsAsErrors = true, NuGet's audit warning (NU1903) is escalated to a hard error, breaking restore for the whole solution.Fix
Add a direct
PackageReferenceforSystem.Security.Cryptography.Xmlpinned to the patched10.0.10version inBuild/_build.csproj, overriding the vulnerable transitive version.Verification
dotnet restore Build\_build.csproj— succeeds, no NU1903.dotnet build Build\_build.csproj— succeeds, 0 warnings/errors.Only touches build tooling; no public API or library changes, so no
api-approvedissue/docs update needed.Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com