fix(build): suppress AngleSharp advisory instead of pinning (corrects ecf6b628)
ecf6b628 pinned AngleSharp to 1.5.2 to clear GHSA-pgww-w46g-26qg. That fixed the
build but BROKE 33 CentralUI bunit tests at runtime with
MissingMethodException: AngleSharp.Dom.IHtmlCollection`1.get_Item(Int32)
because 1.5.x changed IHtmlCollection<T>'s indexer and bunit is compiled against
1.1.x. My mistake: I verified `dotnet build` was clean and did not run the test
suite before committing, so a runtime-only break sailed through.
There is no working patched combination upstream. Verified empirically:
AngleSharp 1.1.2 / 1.2.0 / 1.3.0 / 1.4.0 -> still flagged NU1902
AngleSharp 1.5.0 / 1.5.2 -> patched, but breaks bunit at runtime
bunit up to 2.7.2 (latest) -> still resolves AngleSharp 1.4.0
So the real choice is a suppressed advisory or an unbuildable suite. Scoped
suppression wins here because the reach is nil: AngleSharp is an HTML parser bunit
uses to assert on rendered markup, it ships in no production project, and the only
"documents" it parses are our own components' output.
Explicitly NOT the same call as GHSA-2m69-gcr7-jv3q (SQLitePCLRaw), whose
suppression was removed in 2026-07: that one masked a vulnerability on PRODUCTION
code paths and had a working patched version available. Neither is true here.
Revisit when bunit ships against AngleSharp 1.5+.
Verified:
dotnet build ZB.MOM.WW.ScadaBridge.slnx -> 0 Error(s), 0 Warning(s)
CentralUI.Tests -> 925 passed, 0 failed (was 33 failing)
Claude-Session: https://claude.ai/code/session_01BL2Vu1ESDQ9SCN4gVKkdts
This commit is contained in:
+11
-13
@@ -146,20 +146,18 @@
|
||||
</ItemGroup>
|
||||
|
||||
<!--
|
||||
GHSA-pgww-w46g-26qg (NU1902, moderate) is on AngleSharp 1.1.1, pulled in TRANSITIVELY by
|
||||
bunit into ZB.MOM.WW.ScadaBridge.CentralUI.Tests. With TreatWarningsAsErrors this made the
|
||||
WHOLE SOLUTION BUILD RED — `dotnet build ZB.MOM.WW.ScadaBridge.slnx` failed on clean main,
|
||||
so no test suite could run and every "0 warnings / suite green" gate was unverifiable.
|
||||
GHSA-pgww-w46g-26qg (NU1902, moderate) on AngleSharp, reached only transitively via bunit
|
||||
in ZB.MOM.WW.ScadaBridge.CentralUI.Tests. With TreatWarningsAsErrors it made the WHOLE
|
||||
SOLUTION BUILD RED, so no suite could run and every "0 warnings / green" gate was
|
||||
unverifiable.
|
||||
|
||||
Fixed the same way HistorianGateway fixed the identical break (historiangw @ 6bc005d):
|
||||
an explicit test-only pin to a patched AngleSharp. TEST-ONLY — AngleSharp is a bunit
|
||||
(HTML-parsing) dependency and reaches no production project, so this cannot affect runtime.
|
||||
|
||||
Do not "fix" this by bumping bunit: 2.0.33-preview is the current preview line and still
|
||||
resolves the vulnerable AngleSharp transitively. Pinning the leaf is the fix.
|
||||
Resolved with a scoped NuGetAuditSuppress in that ONE test project (see its csproj for the
|
||||
full rationale) — deliberately NOT a version pin here. A pin was tried first and reverted:
|
||||
AngleSharp >= 1.5.0 is the only patched line, and it changes IHtmlCollection<T>'s indexer,
|
||||
which makes every bunit build throw MissingMethodException at runtime (33 render tests
|
||||
failed). Bumping bunit does not help either — even 2.7.2 resolves AngleSharp 1.4.0, which
|
||||
is still vulnerable. There is no working patched combination upstream today.
|
||||
-->
|
||||
<ItemGroup>
|
||||
<PackageVersion Include="AngleSharp" Version="1.5.2" />
|
||||
</ItemGroup>
|
||||
|
||||
|
||||
</Project>
|
||||
|
||||
+24
-3
@@ -10,9 +10,6 @@
|
||||
|
||||
<ItemGroup>
|
||||
<PackageReference Include="bunit" />
|
||||
<!-- Security pin: GHSA-pgww-w46g-26qg. bunit pulls the vulnerable AngleSharp
|
||||
1.1.1 transitively; 1.5.2 patches it. Test-only, no production reach. -->
|
||||
<PackageReference Include="AngleSharp" />
|
||||
<PackageReference Include="coverlet.collector" />
|
||||
<PackageReference Include="Microsoft.AspNetCore.TestHost" />
|
||||
<PackageReference Include="Microsoft.EntityFrameworkCore.Sqlite" />
|
||||
@@ -43,4 +40,28 @@
|
||||
<ProjectReference Include="../../src/ZB.MOM.WW.ScadaBridge.ConfigurationDatabase/ZB.MOM.WW.ScadaBridge.ConfigurationDatabase.csproj" />
|
||||
</ItemGroup>
|
||||
|
||||
<!--
|
||||
GHSA-pgww-w46g-26qg (NU1902, moderate) on AngleSharp, reached ONLY transitively via
|
||||
bunit. Suppressed here, scoped to this one test project, because there is verifiably
|
||||
no version combination that resolves it:
|
||||
|
||||
- AngleSharp < 1.5.0 is vulnerable (1.4.0 is what even the newest bunit resolves).
|
||||
- AngleSharp >= 1.5.0 changed IHtmlCollection<T>'s indexer, so every bunit build
|
||||
throws MissingMethodException at runtime - 33 CentralUI render tests fail.
|
||||
- Bumping bunit does not help: checked up to 2.7.2, still AngleSharp 1.4.0.
|
||||
|
||||
So the choice is a suppressed advisory or an unbuildable/failing test suite. Scoped
|
||||
suppression wins because the reach is genuinely nil: AngleSharp is an HTML parser used
|
||||
by bunit to assert on rendered markup in unit tests. It ships in no production project
|
||||
and processes no untrusted input - the "documents" it parses are our own components'
|
||||
output. Revisit when bunit ships against AngleSharp 1.5+.
|
||||
|
||||
NOT the same call as GHSA-2m69-gcr7-jv3q (SQLitePCLRaw): that suppression was removed
|
||||
in 2026-07 precisely because it was masking a vulnerability in PRODUCTION code paths.
|
||||
This one is test-only, and a patched-but-working version does not exist upstream.
|
||||
-->
|
||||
<ItemGroup>
|
||||
<NuGetAuditSuppress Include="https://github.com/advisories/GHSA-pgww-w46g-26qg" />
|
||||
</ItemGroup>
|
||||
|
||||
</Project>
|
||||
Reference in New Issue
Block a user