fix(build): suppress AngleSharp advisory instead of pinning (corrects ecf6b628)

ecf6b628 pinned AngleSharp to 1.5.2 to clear GHSA-pgww-w46g-26qg. That fixed the
build but BROKE 33 CentralUI bunit tests at runtime with

    MissingMethodException: AngleSharp.Dom.IHtmlCollection`1.get_Item(Int32)

because 1.5.x changed IHtmlCollection<T>'s indexer and bunit is compiled against
1.1.x. My mistake: I verified `dotnet build` was clean and did not run the test
suite before committing, so a runtime-only break sailed through.

There is no working patched combination upstream. Verified empirically:
  AngleSharp 1.1.2 / 1.2.0 / 1.3.0 / 1.4.0 -> still flagged NU1902
  AngleSharp 1.5.0 / 1.5.2                 -> patched, but breaks bunit at runtime
  bunit up to 2.7.2 (latest)               -> still resolves AngleSharp 1.4.0

So the real choice is a suppressed advisory or an unbuildable suite. Scoped
suppression wins here because the reach is nil: AngleSharp is an HTML parser bunit
uses to assert on rendered markup, it ships in no production project, and the only
"documents" it parses are our own components' output.

Explicitly NOT the same call as GHSA-2m69-gcr7-jv3q (SQLitePCLRaw), whose
suppression was removed in 2026-07: that one masked a vulnerability on PRODUCTION
code paths and had a working patched version available. Neither is true here.
Revisit when bunit ships against AngleSharp 1.5+.

Verified:
  dotnet build ZB.MOM.WW.ScadaBridge.slnx -> 0 Error(s), 0 Warning(s)
  CentralUI.Tests                          -> 925 passed, 0 failed (was 33 failing)

Claude-Session: https://claude.ai/code/session_01BL2Vu1ESDQ9SCN4gVKkdts
This commit is contained in:
Joseph Doherty
2026-07-19 03:14:58 -04:00
parent 7370b33186
commit f056b67e9a
2 changed files with 35 additions and 16 deletions
+11 -13
View File
@@ -146,20 +146,18 @@
</ItemGroup>
<!--
GHSA-pgww-w46g-26qg (NU1902, moderate) is on AngleSharp 1.1.1, pulled in TRANSITIVELY by
bunit into ZB.MOM.WW.ScadaBridge.CentralUI.Tests. With TreatWarningsAsErrors this made the
WHOLE SOLUTION BUILD RED — `dotnet build ZB.MOM.WW.ScadaBridge.slnx` failed on clean main,
so no test suite could run and every "0 warnings / suite green" gate was unverifiable.
GHSA-pgww-w46g-26qg (NU1902, moderate) on AngleSharp, reached only transitively via bunit
in ZB.MOM.WW.ScadaBridge.CentralUI.Tests. With TreatWarningsAsErrors it made the WHOLE
SOLUTION BUILD RED, so no suite could run and every "0 warnings / green" gate was
unverifiable.
Fixed the same way HistorianGateway fixed the identical break (historiangw @ 6bc005d):
an explicit test-only pin to a patched AngleSharp. TEST-ONLY — AngleSharp is a bunit
(HTML-parsing) dependency and reaches no production project, so this cannot affect runtime.
Do not "fix" this by bumping bunit: 2.0.33-preview is the current preview line and still
resolves the vulnerable AngleSharp transitively. Pinning the leaf is the fix.
Resolved with a scoped NuGetAuditSuppress in that ONE test project (see its csproj for the
full rationale) — deliberately NOT a version pin here. A pin was tried first and reverted:
AngleSharp >= 1.5.0 is the only patched line, and it changes IHtmlCollection<T>'s indexer,
which makes every bunit build throw MissingMethodException at runtime (33 render tests
failed). Bumping bunit does not help either — even 2.7.2 resolves AngleSharp 1.4.0, which
is still vulnerable. There is no working patched combination upstream today.
-->
<ItemGroup>
<PackageVersion Include="AngleSharp" Version="1.5.2" />
</ItemGroup>
</Project>
@@ -10,9 +10,6 @@
<ItemGroup>
<PackageReference Include="bunit" />
<!-- Security pin: GHSA-pgww-w46g-26qg. bunit pulls the vulnerable AngleSharp
1.1.1 transitively; 1.5.2 patches it. Test-only, no production reach. -->
<PackageReference Include="AngleSharp" />
<PackageReference Include="coverlet.collector" />
<PackageReference Include="Microsoft.AspNetCore.TestHost" />
<PackageReference Include="Microsoft.EntityFrameworkCore.Sqlite" />
@@ -43,4 +40,28 @@
<ProjectReference Include="../../src/ZB.MOM.WW.ScadaBridge.ConfigurationDatabase/ZB.MOM.WW.ScadaBridge.ConfigurationDatabase.csproj" />
</ItemGroup>
<!--
GHSA-pgww-w46g-26qg (NU1902, moderate) on AngleSharp, reached ONLY transitively via
bunit. Suppressed here, scoped to this one test project, because there is verifiably
no version combination that resolves it:
- AngleSharp < 1.5.0 is vulnerable (1.4.0 is what even the newest bunit resolves).
- AngleSharp >= 1.5.0 changed IHtmlCollection<T>'s indexer, so every bunit build
throws MissingMethodException at runtime - 33 CentralUI render tests fail.
- Bumping bunit does not help: checked up to 2.7.2, still AngleSharp 1.4.0.
So the choice is a suppressed advisory or an unbuildable/failing test suite. Scoped
suppression wins because the reach is genuinely nil: AngleSharp is an HTML parser used
by bunit to assert on rendered markup in unit tests. It ships in no production project
and processes no untrusted input - the "documents" it parses are our own components'
output. Revisit when bunit ships against AngleSharp 1.5+.
NOT the same call as GHSA-2m69-gcr7-jv3q (SQLitePCLRaw): that suppression was removed
in 2026-07 precisely because it was masking a vulnerability in PRODUCTION code paths.
This one is test-only, and a patched-but-working version does not exist upstream.
-->
<ItemGroup>
<NuGetAuditSuppress Include="https://github.com/advisories/GHSA-pgww-w46g-26qg" />
</ItemGroup>
</Project>