feat!: Bump Microsoft.Data.SqlClient to 6.1.6 - #4
Merged
Merged
Conversation
Clears CVE-2024-0056 (high) and CVE-2022-41064 (moderate). 2.1.7 stays on the 2.1.x line and still ships netstandard2.0 and net46 assets, so the published package's target frameworks are unchanged. Also retargets the test project from net46;netcoreapp3.1 to net472;net10.0 and updates the test packages. netcoreapp3.1 is out of support and its targeting packs are gone from current SDKs, and Microsoft.NET.Test.Sdk 18.x requires net462 or later while xunit.runner.visualstudio 3.x requires net472, so net46 could not stay. The library itself still targets net46 and net472 consumes that asset. Adds a GitHub Actions workflow that restores and compiles the solution. Tests are not run there: every fixture reads a connection string from the AzureSqlServerPath environment variable and talks to a live SQL Server. NuGet.Config pointed at the retired nuget.org v2 endpoint, which modern NuGet clients cannot restore from; it now uses v3. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Supersedes the 2.1.7 bump in the previous commit. Adding the build workflow surfaced three more advisories that NuGet Audit reports but Dependabot never alerted on, all transitive under SqlClient 2.1.x: - System.Drawing.Common 4.7.0, critical (GHSA-rxg9-xrhp-64gj), reached via System.Runtime.Caching -> System.Configuration.ConfigurationManager -> System.Security.Permissions -> System.Windows.Extensions - System.IdentityModel.Tokens.Jwt 6.8.0, moderate (GHSA-59j7-ghrg-fj52) - Microsoft.IdentityModel.JsonWebTokens 6.8.0, same advisory 6.1.6 removes the cause rather than pinning around it: it replaced System.Runtime.Caching with Microsoft.Extensions.Caching.Memory, so that whole chain is gone, and it requires the IdentityModel packages at 7.7.1. BREAKING CHANGE: the minimum .NET Framework target goes from net46 to net462, because that is the oldest Framework target SqlClient 6.x ships. Consumers on net46 or net461 must move to net462 or later; net461 and up already resolved against the netstandard2.0 asset. .NET Framework 4.6 and 4.6.1 left Microsoft support in April 2022. Package version goes to 4.0.0 to reflect this. Only SqlConnection and SqlCommand are used from SqlClient, both unchanged, so no source edits were needed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Microsoft.Data.SqlClientwas pinned at 2.0.0, carrying two Dependabot alerts: CVE-2024-0056 (high, a man in the middle can decrypt TLS traffic) and CVE-2022-41064 (moderate, information disclosure).The build could not be verified either way. There was no CI, the test project targeted
netcoreapp3.1whose targeting packs no longer ship with current SDKs, andNuGet.Configpointed at the retired nuget.org v2 endpoint that modern clients cannot restore from.Adding CI then turned up three more advisories that NuGet Audit reports but Dependabot never alerted on, all transitive under SqlClient 2.1.x and all pre-existing under 2.0.0:
System.Drawing.Common4.7.0, critical (GHSA-rxg9-xrhp-64gj), reached viaSystem.Runtime.Caching→System.Configuration.ConfigurationManager→System.Security.Permissions→System.Windows.ExtensionsSystem.IdentityModel.Tokens.Jwt6.8.0, moderate (GHSA-59j7-ghrg-fj52)Microsoft.IdentityModel.JsonWebTokens6.8.0, same advisorySolution
Go to
Microsoft.Data.SqlClient6.1.6 rather than the 2.1.7 Dependabot proposed. 6.x removes the cause of the transitive findings instead of pinning around them: it replacedSystem.Runtime.CachingwithMicrosoft.Extensions.Caching.Memory, so theSystem.Drawing.Commonchain is gone entirely, and it requires the IdentityModel packages at 7.7.1. The build now reports no vulnerability warnings at all.Only
SqlConnectionandSqlCommandare used from SqlClient, both unchanged, so there are no source edits.Retarget the test project to
net472;net10.0and update the test packages.net46could not stay there regardless:Microsoft.NET.Test.Sdk18.x needsnet462or later andxunit.runner.visualstudio3.x needsnet472.Point
NuGet.Configat the v3 endpoint and add a GitHub Actions workflow that restores and builds onwindows-latest. It buildsDebugonly, sinceReleasestrong-name signs against aSqlDatabaseBuilder.snkthat lives in Azure DevOps rather than the repo. It does not run tests: every fixture undertests/reads a connection string fromAzureSqlServerPathand talks to a live SQL Server.Breaking change
The minimum .NET Framework target moves from
net46tonet462, becausenet462is the oldest Framework target SqlClient 6.x ships. .NET Framework support is retained, just not for 4.6 and 4.6.1, both of which left Microsoft support in April 2022. Consumers onnet461and up already resolved against thenetstandard2.0asset. Package version goes to 4.0.0.Note that 6.x also widens the library dependency footprint, pulling in
Azure.Identity,Azure.CoreandMicrosoft.Extensions.Caching.Memory. That is inherent to modern SqlClient.