fix(build): suppress AngleSharp advisory instead of pinning (corrects ecf6b628)
ecf6b628 pinned AngleSharp to 1.5.2 to clear GHSA-pgww-w46g-26qg. That fixed the
build but BROKE 33 CentralUI bunit tests at runtime with
MissingMethodException: AngleSharp.Dom.IHtmlCollection`1.get_Item(Int32)
because 1.5.x changed IHtmlCollection<T>'s indexer and bunit is compiled against
1.1.x. My mistake: I verified `dotnet build` was clean and did not run the test
suite before committing, so a runtime-only break sailed through.
There is no working patched combination upstream. Verified empirically:
AngleSharp 1.1.2 / 1.2.0 / 1.3.0 / 1.4.0 -> still flagged NU1902
AngleSharp 1.5.0 / 1.5.2 -> patched, but breaks bunit at runtime
bunit up to 2.7.2 (latest) -> still resolves AngleSharp 1.4.0
So the real choice is a suppressed advisory or an unbuildable suite. Scoped
suppression wins here because the reach is nil: AngleSharp is an HTML parser bunit
uses to assert on rendered markup, it ships in no production project, and the only
"documents" it parses are our own components' output.
Explicitly NOT the same call as GHSA-2m69-gcr7-jv3q (SQLitePCLRaw), whose
suppression was removed in 2026-07: that one masked a vulnerability on PRODUCTION
code paths and had a working patched version available. Neither is true here.
Revisit when bunit ships against AngleSharp 1.5+.
Verified:
dotnet build ZB.MOM.WW.ScadaBridge.slnx -> 0 Error(s), 0 Warning(s)
CentralUI.Tests -> 925 passed, 0 failed (was 33 failing)
Claude-Session: https://claude.ai/code/session_01BL2Vu1ESDQ9SCN4gVKkdts
This commit is contained in:
+11
-13
@@ -146,20 +146,18 @@
|
||||
</ItemGroup>
|
||||
|
||||
<!--
|
||||
GHSA-pgww-w46g-26qg (NU1902, moderate) is on AngleSharp 1.1.1, pulled in TRANSITIVELY by
|
||||
bunit into ZB.MOM.WW.ScadaBridge.CentralUI.Tests. With TreatWarningsAsErrors this made the
|
||||
WHOLE SOLUTION BUILD RED — `dotnet build ZB.MOM.WW.ScadaBridge.slnx` failed on clean main,
|
||||
so no test suite could run and every "0 warnings / suite green" gate was unverifiable.
|
||||
GHSA-pgww-w46g-26qg (NU1902, moderate) on AngleSharp, reached only transitively via bunit
|
||||
in ZB.MOM.WW.ScadaBridge.CentralUI.Tests. With TreatWarningsAsErrors it made the WHOLE
|
||||
SOLUTION BUILD RED, so no suite could run and every "0 warnings / green" gate was
|
||||
unverifiable.
|
||||
|
||||
Fixed the same way HistorianGateway fixed the identical break (historiangw @ 6bc005d):
|
||||
an explicit test-only pin to a patched AngleSharp. TEST-ONLY — AngleSharp is a bunit
|
||||
(HTML-parsing) dependency and reaches no production project, so this cannot affect runtime.
|
||||
|
||||
Do not "fix" this by bumping bunit: 2.0.33-preview is the current preview line and still
|
||||
resolves the vulnerable AngleSharp transitively. Pinning the leaf is the fix.
|
||||
Resolved with a scoped NuGetAuditSuppress in that ONE test project (see its csproj for the
|
||||
full rationale) — deliberately NOT a version pin here. A pin was tried first and reverted:
|
||||
AngleSharp >= 1.5.0 is the only patched line, and it changes IHtmlCollection<T>'s indexer,
|
||||
which makes every bunit build throw MissingMethodException at runtime (33 render tests
|
||||
failed). Bumping bunit does not help either — even 2.7.2 resolves AngleSharp 1.4.0, which
|
||||
is still vulnerable. There is no working patched combination upstream today.
|
||||
-->
|
||||
<ItemGroup>
|
||||
<PackageVersion Include="AngleSharp" Version="1.5.2" />
|
||||
</ItemGroup>
|
||||
|
||||
|
||||
</Project>
|
||||
|
||||
Reference in New Issue
Block a user