Skip to content

[repo-assist] Fix Snappier and OpenTelemetry.Api security vulnerabilities - #740

Merged
dsyme merged 4 commits into
masterfrom
repo-assist/eng-security-deps-20260913-8763689f4d1352b2
Sep 27, 2026
Merged

dsyme merged 4 commits into
masterfrom
repo-assist/eng-security-deps-20260913-8763689f4d1352b2

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

🤖 This PR was created by Repo Assist, an automated AI assistant. Please review carefully before merging.

Summary

Pins two transitive dependencies to patched versions, resolving both currently-known NuGet advisories on this repository:

  1. Snappier >= 1.3.1 (transitive via Parquet.Net) — fixes GHSA-pggp-6c3x-2xmx / CVE-2026-44302, a high severity (CVSS 7.5) infinite-loop denial-of-service in SnappyStream decompression triggerable by a malformed 15-byte framed-Snappy input. No exception is thrown, so callers cannot recover via try/catch.
  2. OpenTelemetry.Api >= 1.15.3 (transitive, likely via BenchmarkDotNet/test SDK chain) — fixes GHSA-g94r-2vxg-569j / CVE-2026-40894, a moderate severity (CVSS 5.3) excessive-memory-allocation issue when parsing baggage/B3/Jaeger propagation headers.

Both are minimal paket.dependencies pins — no source code changes.

Rationale

  • Snappier 1.3.0 (the version resolved before this change) is within the vulnerable range (<= 1.3.0); the first patched version is 1.3.1.
  • OpenTelemetry.Api 1.15.1 (resolved before this change) is within the vulnerable range (>= 0.5.0-beta.2, < 1.15.3); the first patched version is 1.15.3. After adding the pin, paket resolves it to 1.18 (satisfies >= 1.15.3).
  • Both packages are only pulled in transitively (Snappier via Parquet.Net, OpenTelemetry.Api via the BenchmarkDotNet/test toolchain), so an explicit top-level nuget pin in paket.dependencies is the standard, minimal way to force paket to resolve the patched version without waiting on upstream packages to bump their own dependency ranges.

Trade-offs

  • None identified. Both changes are patch/point-release bumps of transitive dependencies; no Deedle API surface is affected.

Test Status

  • ✅ dotnet paket install — resolved cleanly; paket.lock diff is limited to the Snappier and OpenTelemetry.Api version bumps.
  • ✅ Clean dotnet restore Deedle.sln (after clearing obj/ caches) — the NU1902/NU1903 vulnerability warnings for both packages no longer appear.
  • ✅ ./build.sh — full solution + docs build succeeded.
  • ✅ dotnet test tests/Deedle.Tests/Deedle.Tests.fsproj -c Release — 928/928 passed.
  • ✅ dotnet test tests/Deedle.Parquet.Tests/Deedle.Parquet.Tests.fsproj -c Release — 55/55 passed (exercises the Snappier-dependent Parquet codec path).

Updated RELEASE_NOTES.md under the unreleased 8.1.0 section (new Infrastructure entry).

Notes for maintainers

A previous Repo Assist run (PR #735, still open) attempted a similar Snappier fix bundled with an fsdocs-tool bump in .config/dotnet-tools.json, but that PR could not be pushed automatically because .config/dotnet-tools.json is a protected file requiring workflows permission. This PR only touches paket.dependencies/paket.lock/RELEASE_NOTES.md (no protected files), and additionally fixes the previously-unaddressed OpenTelemetry.Api advisory. Maintainers may wish to close #735 once this PR is reviewed, and separately consider the fsdocs-tool bump on its own.


Repo Assist never merges PRs itself — a human maintainer should review and merge.

Generated by 🌈 Repo Assist, see workflow run. Learn more.
Comment /repo-assist to run again

Add this agentic workflow to your repo

To install this agentic workflow, run

gh aw add githubnext/agentics/workflows/repo-assist.md@ae8d551f07c7ed7619f8c58c7bb4c3ac89395d38

Pins two transitive dependencies to patched versions:
- Snappier >= 1.3.1 (via Parquet.Net) fixes GHSA-pggp-6c3x-2xmx
  (high severity infinite-loop DoS during SnappyStream decompression)
- OpenTelemetry.Api >= 1.15.3 fixes GHSA-g94r-2vxg-569j
  (moderate severity excessive memory allocation when parsing
  propagation headers)

Both are minimal paket.dependencies pins with no source changes.
Verified with a clean restore that NU1902/NU1903 vulnerability
warnings no longer appear, and that the full test suite passes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@dsyme
dsyme marked this pull request as ready for review September 14, 2026 12:54
dsyme pushed a commit that referenced this pull request Sep 27, 2026
🤖 *This PR was created by Repo Assist, an automated AI assistant. Please
review carefully before merging.*

## Summary

Low-risk engineering maintenance: updates `NUnit3TestAdapter` (and its
transitive `Microsoft.Testing.Platform`/`Microsoft.NET.Test.Sdk` chain)
to the latest patch/minor-compatible resolution, using `dotnet paket
update NUnit3TestAdapter --keep-major` to keep the update conservative.

Resulting version bumps (all test-infrastructure packages, no Deedle
library dependencies touched):

- `Microsoft.Testing.Platform` 2.1 → 2.4.1
- `Microsoft.Testing.Platform.MSBuild` 2.1 → 2.4.1
- `Microsoft.Testing.Extensions.Telemetry` / `.TrxReport.Abstractions` /
`.VSTestBridge` 2.1 → 2.4.1
- `Microsoft.TestPlatform.ObjectModel` / `.TestHost` 18.3 → 18.10.1

## Rationale

These are the test-execution toolchain components (used only at test-run
time, never shipped in the Deedle/Deedle.Parquet NuGet packages).
Keeping them current reduces the chance of hitting compatibility issues
with newer `dotnet test` / VSTest tooling, and is a routine low-risk
maintenance task.

## Trade-offs

None identified — purely a test-tooling update; the `--keep-major` flag
was used to avoid pulling in any major-version jumps. No source or
public API changes.

## Test Status

- ✅ `dotnet build Deedle.sln -c Release` — 0 errors (31 pre-existing
warnings unrelated to this change).
- ✅ `dotnet test tests/Deedle.Tests/Deedle.Tests.fsproj -c Release` —
928/928 passed.
- ✅ `dotnet test tests/Deedle.Parquet.Tests/Deedle.Parquet.Tests.fsproj
-c Release` — 55/55 passed.

## Notes for maintainers

This is unrelated to the still-open security-advisory PR #740
(Snappier/OpenTelemetry.Api pins) — no overlap, both can be merged
independently.

> Repo Assist never merges PRs itself — a human maintainer should review
and merge.

> Generated by 🌈 Repo Assist, see [workflow
run](https://github.com/fslaborg/Deedle/actions/runs/35489056215).
[Learn
more](https://github.com/githubnext/agentics/blob/main/docs/repo-assist.md).
> <sub>Comment <em>/repo-assist</em> to run again</sub>
>
<details>
<summary><sub>Add this agentic workflow to your repo</sub></summary>

To install this agentic workflow, run

```
gh aw add githubnext/agentics@4bc8419
```
</details>


<!-- gh-aw-agentic-workflow: Repo Assist, engine: copilot, model: auto,
id: 35489056215, workflow_id: repo-assist, run:
https://github.com/fslaborg/Deedle/actions/runs/35489056215 -->

<!-- gh-aw-workflow-id: repo-assist -->
<!-- gh-aw-workflow-call-id: fslaborg/Deedle/repo-assist -->

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@dsyme

dsyme commented Sep 27, 2026

Copy link
Copy Markdown
Member

/repo-assist merge with main, resolve conflicts and regenerate the paket.lock file

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

✗ Repo Assist encountered failed to deliver outputs, see workflow run.

Generated by 🌈 Repo Assist, see workflow run. Learn more.

Regenerate paket.lock after resolving dependency updates.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@dsyme

dsyme commented Sep 27, 2026

Copy link
Copy Markdown
Member

/repo-assist fix failing CI

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

✓ Repo Assist completed successfully, see workflow run.

Generated by 🌈 Repo Assist, see workflow run. Learn more.

The merge with master let paket's unconstrained `nuget NUnit` and
`nuget Parquet.Net` lines resolve to NUnit 5.0 and Parquet.Net 6.1.

- NUnit 5.0 removed `NUnit.Framework.TestDelegate`, which FsUnit 7.1.1's
  `should` operator and tests/Deedle.Tests/VirtualVector.fs still
  reference, causing build errors and TypeLoadException test failures.
- Parquet.Net 6.1 renamed/removed APIs (`DataColumn`, `WriteColumnAsync`,
  `ReadEntireRowGroupAsync`, IDisposable support) used throughout
  src/Deedle.Parquet/Parquet.fs and VirtualParquetSource.fs, causing
  build errors.

Pinned `NUnit ~> 4.5.1` and `Parquet.Net < 6.0` in paket.dependencies to
restore the previously-tested, working versions while keeping the
Snappier/OpenTelemetry.Api security pins intact.

Verified: dotnet build Deedle.sln -c Release succeeds with 0 errors,
and dotnet test Deedle.sln -c Release passes all test projects
(Deedle.Tests 947/947, Deedle.Parquet.Tests 55/55, and all others).

🤖 This commit was made by Repo Assist, an automated AI assistant, in
response to a maintainer request to fix failing CI on this PR.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor Author

🤖 This is an automated response from Repo Assist.

CI failure fixed and pushed. Root cause: the merge with master let paket resolve unconstrained NUnit and Parquet.Net references up to NUnit 5.0 and Parquet.Net 6.1.

  • NUnit 5.0 removed NUnit.Framework.TestDelegate, which FsUnit 7.1.1's should operator (and tests/Deedle.Tests/VirtualVector.fs) still reference — this caused the TypeLoadException failures across almost every test project.
  • Parquet.Net 6.1 renamed/removed several APIs (DataColumn, WriteColumnAsync, ReadEntireRowGroupAsync, IDisposable support) that src/Deedle.Parquet/Parquet.fs and VirtualParquetSource.fs rely on — this caused the build-ubuntu/build-windows compile errors.

Fix: pinned NUnit ~> 4.5.1 and Parquet.Net < 6.0 in paket.dependencies (restoring the previously-tested versions), while keeping the Snappier >= 1.3.1 / OpenTelemetry.Api >= 1.15.3 security pins from this PR intact, and regenerated paket.lock.

Test Status

  • ✅ dotnet build Deedle.sln -c Release — 0 errors.
  • ✅ dotnet test Deedle.sln -c Release — all projects pass, including Deedle.Tests (947/947) and Deedle.Parquet.Tests (55/55).

Generated by 🌈 Repo Assist, see workflow run. Learn more.
Comment /repo-assist to run again

Add this agentic workflow to your repo

To install this agentic workflow, run

gh aw add githubnext/agentics/workflows/repo-assist.md@4bc8419fad05e6b032741cbfd189986700bcf71c

@dsyme
dsyme merged commit dbd6a7c into master Sep 27, 2026
2 checks passed
@dsyme
dsyme deleted the repo-assist/eng-security-deps-20260913-8763689f4d1352b2 branch September 27, 2026 18:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[repo-assist] Fix Snappier high-severity vulnerability, update fsdocs-tool

1 participant