[repo-assist] Fix Snappier and OpenTelemetry.Api security vulnerabilities - #740
Conversation
Pins two transitive dependencies to patched versions: - Snappier >= 1.3.1 (via Parquet.Net) fixes GHSA-pggp-6c3x-2xmx (high severity infinite-loop DoS during SnappyStream decompression) - OpenTelemetry.Api >= 1.15.3 fixes GHSA-g94r-2vxg-569j (moderate severity excessive memory allocation when parsing propagation headers) Both are minimal paket.dependencies pins with no source changes. Verified with a clean restore that NU1902/NU1903 vulnerability warnings no longer appear, and that the full test suite passes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
🤖 *This PR was created by Repo Assist, an automated AI assistant. Please review carefully before merging.* ## Summary Low-risk engineering maintenance: updates `NUnit3TestAdapter` (and its transitive `Microsoft.Testing.Platform`/`Microsoft.NET.Test.Sdk` chain) to the latest patch/minor-compatible resolution, using `dotnet paket update NUnit3TestAdapter --keep-major` to keep the update conservative. Resulting version bumps (all test-infrastructure packages, no Deedle library dependencies touched): - `Microsoft.Testing.Platform` 2.1 → 2.4.1 - `Microsoft.Testing.Platform.MSBuild` 2.1 → 2.4.1 - `Microsoft.Testing.Extensions.Telemetry` / `.TrxReport.Abstractions` / `.VSTestBridge` 2.1 → 2.4.1 - `Microsoft.TestPlatform.ObjectModel` / `.TestHost` 18.3 → 18.10.1 ## Rationale These are the test-execution toolchain components (used only at test-run time, never shipped in the Deedle/Deedle.Parquet NuGet packages). Keeping them current reduces the chance of hitting compatibility issues with newer `dotnet test` / VSTest tooling, and is a routine low-risk maintenance task. ## Trade-offs None identified — purely a test-tooling update; the `--keep-major` flag was used to avoid pulling in any major-version jumps. No source or public API changes. ## Test Status - ✅ `dotnet build Deedle.sln -c Release` — 0 errors (31 pre-existing warnings unrelated to this change). - ✅ `dotnet test tests/Deedle.Tests/Deedle.Tests.fsproj -c Release` — 928/928 passed. - ✅ `dotnet test tests/Deedle.Parquet.Tests/Deedle.Parquet.Tests.fsproj -c Release` — 55/55 passed. ## Notes for maintainers This is unrelated to the still-open security-advisory PR #740 (Snappier/OpenTelemetry.Api pins) — no overlap, both can be merged independently. > Repo Assist never merges PRs itself — a human maintainer should review and merge. > Generated by 🌈 Repo Assist, see [workflow run](https://github.com/fslaborg/Deedle/actions/runs/35489056215). [Learn more](https://github.com/githubnext/agentics/blob/main/docs/repo-assist.md). > <sub>Comment <em>/repo-assist</em> to run again</sub> > <details> <summary><sub>Add this agentic workflow to your repo</sub></summary> To install this agentic workflow, run ``` gh aw add githubnext/agentics@4bc8419 ``` </details> <!-- gh-aw-agentic-workflow: Repo Assist, engine: copilot, model: auto, id: 35489056215, workflow_id: repo-assist, run: https://github.com/fslaborg/Deedle/actions/runs/35489056215 --> <!-- gh-aw-workflow-id: repo-assist --> <!-- gh-aw-workflow-call-id: fslaborg/Deedle/repo-assist --> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
/repo-assist merge with main, resolve conflicts and regenerate the paket.lock file |
|
✗ Repo Assist encountered failed to deliver outputs, see workflow run.
|
Regenerate paket.lock after resolving dependency updates. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
/repo-assist fix failing CI |
|
✓ Repo Assist completed successfully, see workflow run.
|
The merge with master let paket's unconstrained `nuget NUnit` and `nuget Parquet.Net` lines resolve to NUnit 5.0 and Parquet.Net 6.1. - NUnit 5.0 removed `NUnit.Framework.TestDelegate`, which FsUnit 7.1.1's `should` operator and tests/Deedle.Tests/VirtualVector.fs still reference, causing build errors and TypeLoadException test failures. - Parquet.Net 6.1 renamed/removed APIs (`DataColumn`, `WriteColumnAsync`, `ReadEntireRowGroupAsync`, IDisposable support) used throughout src/Deedle.Parquet/Parquet.fs and VirtualParquetSource.fs, causing build errors. Pinned `NUnit ~> 4.5.1` and `Parquet.Net < 6.0` in paket.dependencies to restore the previously-tested, working versions while keeping the Snappier/OpenTelemetry.Api security pins intact. Verified: dotnet build Deedle.sln -c Release succeeds with 0 errors, and dotnet test Deedle.sln -c Release passes all test projects (Deedle.Tests 947/947, Deedle.Parquet.Tests 55/55, and all others). 🤖 This commit was made by Repo Assist, an automated AI assistant, in response to a maintainer request to fix failing CI on this PR. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
🤖 This is an automated response from Repo Assist. CI failure fixed and pushed. Root cause: the merge with
Fix: pinned Test Status
Add this agentic workflow to your repoTo install this agentic workflow, run |
🤖 This PR was created by Repo Assist, an automated AI assistant. Please review carefully before merging.
Summary
Pins two transitive dependencies to patched versions, resolving both currently-known NuGet advisories on this repository:
Snappier >= 1.3.1(transitive viaParquet.Net) — fixes GHSA-pggp-6c3x-2xmx / CVE-2026-44302, a high severity (CVSS 7.5) infinite-loop denial-of-service inSnappyStreamdecompression triggerable by a malformed 15-byte framed-Snappy input. No exception is thrown, so callers cannot recover viatry/catch.OpenTelemetry.Api >= 1.15.3(transitive, likely viaBenchmarkDotNet/test SDK chain) — fixes GHSA-g94r-2vxg-569j / CVE-2026-40894, a moderate severity (CVSS 5.3) excessive-memory-allocation issue when parsing baggage/B3/Jaeger propagation headers.Both are minimal
paket.dependenciespins — no source code changes.Rationale
<= 1.3.0); the first patched version is1.3.1.>= 0.5.0-beta.2, < 1.15.3); the first patched version is1.15.3. After adding the pin, paket resolves it to1.18(satisfies>= 1.15.3).Parquet.Net, OpenTelemetry.Api via the BenchmarkDotNet/test toolchain), so an explicit top-levelnugetpin inpaket.dependenciesis the standard, minimal way to force paket to resolve the patched version without waiting on upstream packages to bump their own dependency ranges.Trade-offs
Test Status
dotnet paket install— resolved cleanly;paket.lockdiff is limited to theSnappierandOpenTelemetry.Apiversion bumps.dotnet restore Deedle.sln(after clearingobj/caches) — theNU1902/NU1903vulnerability warnings for both packages no longer appear../build.sh— full solution + docs build succeeded.dotnet test tests/Deedle.Tests/Deedle.Tests.fsproj -c Release— 928/928 passed.dotnet test tests/Deedle.Parquet.Tests/Deedle.Parquet.Tests.fsproj -c Release— 55/55 passed (exercises the Snappier-dependent Parquet codec path).Updated
RELEASE_NOTES.mdunder the unreleased8.1.0section (new Infrastructure entry).Notes for maintainers
A previous Repo Assist run (PR #735, still open) attempted a similar Snappier fix bundled with an
fsdocs-toolbump in.config/dotnet-tools.json, but that PR could not be pushed automatically because.config/dotnet-tools.jsonis a protected file requiringworkflowspermission. This PR only touchespaket.dependencies/paket.lock/RELEASE_NOTES.md(no protected files), and additionally fixes the previously-unaddressedOpenTelemetry.Apiadvisory. Maintainers may wish to close #735 once this PR is reviewed, and separately consider thefsdocs-toolbump on its own.Add this agentic workflow to your repo
To install this agentic workflow, run