Skip to content

Bump L10NSharp, SIL.BuildTasks, and related deps to close known vulnerabilities - #1543

Merged
tombogle merged 11 commits into
masterfrom
update-dependencies
Oct 8, 2026
Merged

tombogle merged 11 commits into
masterfrom
update-dependencies

Conversation

@tombogle

@tombogle tombogle commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Upgrades L10NSharp/L10NSharp.Windows.Forms to 11.0.1, SIL.ReleaseTasks/SIL.BuildTasks to 4.0.0, Markdig.Signed to 1.4.0, FFMpegCore to 5.5.0, and icu.net to 4.0.0 (released alongside this PR), plus the System.Memory/System.Resources.Extensions version alignment needed to keep restore consistent across the solution. Also removes now-unused System.Net.Http/System.IO.Compression/System.Globalization packages and their legacy System.Private.Uri vulnerability chain.


This change is Reviewable

@tombogle tombogle self-assigned this Sep 10, 2026
@tombogle tombogle added the dependencies Pull requests that update a dependency file label Sep 10, 2026
@github-actions

github-actions Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Palaso Tests

     4 files  ± 0       4 suites  ±0   10m 45s ⏱️ - 1m 20s
 5 176 tests + 7   4 933 ✅ + 7  243 💤 ±0  0 ❌ ±0 
16 865 runs  +21  16 111 ✅ +23  754 💤  - 2  0 ❌ ±0 

Results for commit 6c59267. ± Comparison against base commit 4475678.

♻️ This comment has been updated with latest results.

@imnasnainaec

This comment was marked as off-topic.

imnasnainaec

This comment was marked as resolved.

@tombogle

Copy link
Copy Markdown
Contributor Author

CHANGELOG.md line 93 at r1 (raw file):

Previously, imnasnainaec (D. Ror.) wrote…

For version alignment, should SIL.Scripture.Tests have

<PackageReference Include="System.Resources.Extensions" Version="6.0.0" />

bumped to 10.0.11?

Done

@tombogle

Copy link
Copy Markdown
Contributor Author

DRAFT: Worth considering waiting for sillsdev/SIL.BuildTasks#90 and getting a new release through the ranks in order to simplify this PR.

tombogle and others added 9 commits September 25, 2026 17:06
…rabilities

Upgrades L10NSharp/L10NSharp.Windows.Forms to 11.0.0 and SIL.BuildTasks to
3.3.0, plus the System.Memory/System.Resources.Extensions/FFMpegCore/icu.net
version alignment needed to keep restore consistent across the solution.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ins.Annotations,

NUnit, System.Configuration.ConfigurationManager, System.Resources.Extensions,
and a netstandard2.0-only SIL.ReleaseTasks/Markdig.Signed bump

SIL.ReleaseTasks 3.3.0 pulls in Microsoft.Build.Tasks.Core, which has no net462/net48
asset and disrupts implicit WindowsBase/System.IO.Packaging resolution when consumed
via its netstandard2.0 fallback there, so it's split per-TFM: netstandard2.0-targeting
projects get 3.3.0 (and the Markdig.Signed 0.41.1 floor it requires), net462/net48 stay
on 3.1.1/0.37.0. net8.0-windows projects that transitively consume the netstandard2.0
build of SIL.Core/SIL.WritingSystems get the same Markdig.Signed bump to match.

Also adds unit test coverage for two previously-untested code paths this touches:
Markdig rendering in ShowReleaseNotesDialog, and the ConfigurationManager-backed
FactoryPassword fallback in SettingsProtectionSingleton.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…xtensions

version and a stale hardcoded NUnit copyright-year assertion

SIL.Scripture.Tests still had System.Resources.Extensions pinned at 6.0.0,
which conflicted at runtime with the 10.0.12 pulled in transitively via
SIL.Windows.Forms.Scripture.Tests's other references, causing a
FileLoadException on net48 (assembly manifest mismatch between the two
resolved versions). Bumped it to 10.0.12 to match the rest of the graph.

AcknowledgementAttributeTests.CreateAnAcknowledgement_NoCopyright_OverriddenByFile
hardcoded NUnit's embedded copyright year, which changed for real between
3.13.3 and 3.14.0. Reworked it (and its NoName sibling) to compare against
FileVersionInfo read directly from the DLL, so they test the actual behavior
instead of a value that goes stale on every future NUnit bump.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…t NUnit's

Comparing against FileVersionInfo read live from the DLL (the previous fix)
sidesteps breaking on every NUnit bump, but does so by computing the expected
value the same way the production code does, which is less obvious to read
and weaker at catching a real regression in AcknowledgementAttribute itself.

Pointing at this test assembly instead restores a literal, readable expected
value (its Copyright/ProductName come from Directory.Build.props, which we
only change deliberately) while still being immune to third-party dependency
churn.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…nt range

The exact end year in Directory.Build.props's <Copyright> gets bumped
annually, so hardcoding it meant the test would need editing on the same
cadence. Keep the fixed text ("Copyright © 2010-...SIL Global") asserted
exactly, but accept any year within the last 3 (and not in the future),
so routine annual bumps don't require a matching test change while a
genuinely stale or mistyped year still fails.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Upgraded test app to use latest localized strings
Added required explicit reference to System.Memory 4.6.3
Bumps SIL.WritingSystems/SIL.Windows.Forms.Keyboarding to icu.net 4.0.0
(released to fix its own vulnerable Newtonsoft.Json/System.Private.Uri
chain) and drops the temporary Microsoft.Extensions.DependencyModel
override now that icu.net floors it correctly on its own.

Fixes the shared-output-folder version-split hazard for
System.Resources.Extensions the same way it was already fixed for
System.Memory: SIL.Core.Desktop and SIL.Windows.Forms.Keyboarding only
floored it at 10.0.11 via L10NSharp, while SIL.Windows.Forms/SIL.Media/
SIL.Scripture.Tests already pinned 10.0.12, so whichever version was
built last intermittently broke the other (reproduced via
SIL.Windows.Forms.Scripture.Tests). Also drops the now-redundant
System.Memory pin in SIL.Core, since Markdig.Signed 1.4.0 already
floors it at 4.6.3 on its own.

Removes now-unused System.Globalization/System.IO.Compression/
System.Net.Http package references in favor of the BCL types already
available on net462/net48, closing out their legacy
System.Private.Uri 4.3.0 vulnerability chain.

Updates CHANGELOG.md to match: corrects stale version references
(FFMpegCore 5.5.0, L10NSharp's true 11.0.1 floor), completes the
Markdig.Signed bump's project list, and flags it as a subtle/unlikely
breaking change per SemVer's 0.x->1.x boundary.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@tombogle
tombogle marked this pull request as ready for review September 28, 2026 17:55
@tombogle

Copy link
Copy Markdown
Contributor Author

Ready for review, but kind of waiting to see if there is any further feedback on the ICU version question.

@andrew-polk andrew-polk left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@andrew-polk reviewed 56 files and all commit messages, and made 1 comment.
Reviewable status: all files reviewed, 1 unresolved discussion (waiting on imnasnainaec and tombogle).


Palaso.sln line 3 at r4 (raw file):

Microsoft Visual Studio Solution File, Format Version 12.00
# Visual Studio Version 18
VisualStudioVersion = 18.9.12128.139 oobstable

Um. Someone started typing not knowing their cursor was here?

@tombogle

tombogle commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Palaso.sln line 3 at r4 (raw file):

Previously, andrew-polk wrote…

Um. Someone started typing not knowing their cursor was here?

oobstable is VS's internal release-channel tag (short for "out-of-band stable"). It's just metadata VS appends automatically and has no effect on the build.

@andrew-polk andrew-polk left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@andrew-polk made 1 comment and resolved 1 discussion.
Reviewable status: :shipit: complete! all files reviewed, all discussions resolved (waiting on imnasnainaec).


Palaso.sln line 3 at r4 (raw file):

Previously, tombogle (Tom Bogle) wrote…

oobstable is VS's internal release-channel tag (short for "out-of-band stable"). It's just metadata VS appends automatically and has no effect on the build.

Thanks. Funny that my quick google didn't find it. But I guess it assumed it was a typo.
Sorry; carry on.

@tombogle
tombogle enabled auto-merge (squash) October 8, 2026 21:42

@imnasnainaec imnasnainaec left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@imnasnainaec partially reviewed 15 files and all commit messages.
Reviewable status: :shipit: complete! all files reviewed, all discussions resolved (waiting on tombogle).

@tombogle
tombogle merged commit c0e20ac into master Oct 8, 2026
11 checks passed
@tombogle
tombogle deleted the update-dependencies branch October 8, 2026 21:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants