Repository navigation
Bump L10NSharp, SIL.BuildTasks, and related deps to close known vulnerabilities - #1543
Conversation
This comment was marked as off-topic.
This comment was marked as off-topic.
f4c92b6 to
3bd77a7
Compare
|
Previously, imnasnainaec (D. Ror.) wrote…
Done |
a0ad33f to
d262924
Compare
|
DRAFT: Worth considering waiting for sillsdev/SIL.BuildTasks#90 and getting a new release through the ranks in order to simplify this PR. |
…rabilities Upgrades L10NSharp/L10NSharp.Windows.Forms to 11.0.0 and SIL.BuildTasks to 3.3.0, plus the System.Memory/System.Resources.Extensions/FFMpegCore/icu.net version alignment needed to keep restore consistent across the solution. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ins.Annotations, NUnit, System.Configuration.ConfigurationManager, System.Resources.Extensions, and a netstandard2.0-only SIL.ReleaseTasks/Markdig.Signed bump SIL.ReleaseTasks 3.3.0 pulls in Microsoft.Build.Tasks.Core, which has no net462/net48 asset and disrupts implicit WindowsBase/System.IO.Packaging resolution when consumed via its netstandard2.0 fallback there, so it's split per-TFM: netstandard2.0-targeting projects get 3.3.0 (and the Markdig.Signed 0.41.1 floor it requires), net462/net48 stay on 3.1.1/0.37.0. net8.0-windows projects that transitively consume the netstandard2.0 build of SIL.Core/SIL.WritingSystems get the same Markdig.Signed bump to match. Also adds unit test coverage for two previously-untested code paths this touches: Markdig rendering in ShowReleaseNotesDialog, and the ConfigurationManager-backed FactoryPassword fallback in SettingsProtectionSingleton. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…xtensions version and a stale hardcoded NUnit copyright-year assertion SIL.Scripture.Tests still had System.Resources.Extensions pinned at 6.0.0, which conflicted at runtime with the 10.0.12 pulled in transitively via SIL.Windows.Forms.Scripture.Tests's other references, causing a FileLoadException on net48 (assembly manifest mismatch between the two resolved versions). Bumped it to 10.0.12 to match the rest of the graph. AcknowledgementAttributeTests.CreateAnAcknowledgement_NoCopyright_OverriddenByFile hardcoded NUnit's embedded copyright year, which changed for real between 3.13.3 and 3.14.0. Reworked it (and its NoName sibling) to compare against FileVersionInfo read directly from the DLL, so they test the actual behavior instead of a value that goes stale on every future NUnit bump. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…t NUnit's Comparing against FileVersionInfo read live from the DLL (the previous fix) sidesteps breaking on every NUnit bump, but does so by computing the expected value the same way the production code does, which is less obvious to read and weaker at catching a real regression in AcknowledgementAttribute itself. Pointing at this test assembly instead restores a literal, readable expected value (its Copyright/ProductName come from Directory.Build.props, which we only change deliberately) while still being immune to third-party dependency churn. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…nt range
The exact end year in Directory.Build.props's <Copyright> gets bumped
annually, so hardcoding it meant the test would need editing on the same
cadence. Keep the fixed text ("Copyright © 2010-...SIL Global") asserted
exactly, but accept any year within the last 3 (and not in the future),
so routine annual bumps don't require a matching test change while a
genuinely stale or mistyped year still fails.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Upgraded test app to use latest localized strings
Added required explicit reference to System.Memory 4.6.3
Bumps SIL.WritingSystems/SIL.Windows.Forms.Keyboarding to icu.net 4.0.0 (released to fix its own vulnerable Newtonsoft.Json/System.Private.Uri chain) and drops the temporary Microsoft.Extensions.DependencyModel override now that icu.net floors it correctly on its own. Fixes the shared-output-folder version-split hazard for System.Resources.Extensions the same way it was already fixed for System.Memory: SIL.Core.Desktop and SIL.Windows.Forms.Keyboarding only floored it at 10.0.11 via L10NSharp, while SIL.Windows.Forms/SIL.Media/ SIL.Scripture.Tests already pinned 10.0.12, so whichever version was built last intermittently broke the other (reproduced via SIL.Windows.Forms.Scripture.Tests). Also drops the now-redundant System.Memory pin in SIL.Core, since Markdig.Signed 1.4.0 already floors it at 4.6.3 on its own. Removes now-unused System.Globalization/System.IO.Compression/ System.Net.Http package references in favor of the BCL types already available on net462/net48, closing out their legacy System.Private.Uri 4.3.0 vulnerability chain. Updates CHANGELOG.md to match: corrects stale version references (FFMpegCore 5.5.0, L10NSharp's true 11.0.1 floor), completes the Markdig.Signed bump's project list, and flags it as a subtle/unlikely breaking change per SemVer's 0.x->1.x boundary. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
476564d to
378bd0b
Compare
|
Ready for review, but kind of waiting to see if there is any further feedback on the ICU version question. |
andrew-polk
left a comment
There was a problem hiding this comment.
@andrew-polk reviewed 56 files and all commit messages, and made 1 comment.
Reviewable status: all files reviewed, 1 unresolved discussion (waiting on imnasnainaec and tombogle).
Palaso.sln line 3 at r4 (raw file):
Microsoft Visual Studio Solution File, Format Version 12.00 # Visual Studio Version 18 VisualStudioVersion = 18.9.12128.139 oobstable
Um. Someone started typing not knowing their cursor was here?
|
Previously, andrew-polk wrote…
|
andrew-polk
left a comment
There was a problem hiding this comment.
@andrew-polk made 1 comment and resolved 1 discussion.
Reviewable status:complete! all files reviewed, all discussions resolved (waiting on imnasnainaec).
Palaso.sln line 3 at r4 (raw file):
Previously, tombogle (Tom Bogle) wrote…
oobstableis VS's internal release-channel tag (short for "out-of-band stable"). It's just metadata VS appends automatically and has no effect on the build.
Thanks. Funny that my quick google didn't find it. But I guess it assumed it was a typo.
Sorry; carry on.
imnasnainaec
left a comment
There was a problem hiding this comment.
@imnasnainaec partially reviewed 15 files and all commit messages.
Reviewable status:complete! all files reviewed, all discussions resolved (waiting on tombogle).
Upgrades L10NSharp/L10NSharp.Windows.Forms to 11.0.1, SIL.ReleaseTasks/SIL.BuildTasks to 4.0.0, Markdig.Signed to 1.4.0, FFMpegCore to 5.5.0, and icu.net to 4.0.0 (released alongside this PR), plus the System.Memory/System.Resources.Extensions version alignment needed to keep restore consistent across the solution. Also removes now-unused System.Net.Http/System.IO.Compression/System.Globalization packages and their legacy System.Private.Uri vulnerability chain.
This change is