Skip to content

feat!: Bump Microsoft.Data.SqlClient to 6.1.6 - #4

Merged
Xtrimmer merged 2 commits into
masterfrom
jtrimmer/fix-dependabot-alerts
Aug 12, 2026
Merged

Xtrimmer merged 2 commits into
masterfrom
jtrimmer/fix-dependabot-alerts

Conversation

@Xtrimmer

@Xtrimmer Xtrimmer commented Aug 12, 2026 •

Copy link
Copy Markdown
Owner

Problem

Microsoft.Data.SqlClient was pinned at 2.0.0, carrying two Dependabot alerts: CVE-2024-0056 (high, a man in the middle can decrypt TLS traffic) and CVE-2022-41064 (moderate, information disclosure).

The build could not be verified either way. There was no CI, the test project targeted netcoreapp3.1 whose targeting packs no longer ship with current SDKs, and NuGet.Config pointed at the retired nuget.org v2 endpoint that modern clients cannot restore from.

Adding CI then turned up three more advisories that NuGet Audit reports but Dependabot never alerted on, all transitive under SqlClient 2.1.x and all pre-existing under 2.0.0:

  • System.Drawing.Common 4.7.0, critical (GHSA-rxg9-xrhp-64gj), reached via System.Runtime.Caching → System.Configuration.ConfigurationManager → System.Security.Permissions → System.Windows.Extensions
  • System.IdentityModel.Tokens.Jwt 6.8.0, moderate (GHSA-59j7-ghrg-fj52)
  • Microsoft.IdentityModel.JsonWebTokens 6.8.0, same advisory

Solution

Go to Microsoft.Data.SqlClient 6.1.6 rather than the 2.1.7 Dependabot proposed. 6.x removes the cause of the transitive findings instead of pinning around them: it replaced System.Runtime.Caching with Microsoft.Extensions.Caching.Memory, so the System.Drawing.Common chain is gone entirely, and it requires the IdentityModel packages at 7.7.1. The build now reports no vulnerability warnings at all.

Only SqlConnection and SqlCommand are used from SqlClient, both unchanged, so there are no source edits.

Retarget the test project to net472;net10.0 and update the test packages. net46 could not stay there regardless: Microsoft.NET.Test.Sdk 18.x needs net462 or later and xunit.runner.visualstudio 3.x needs net472.

Point NuGet.Config at the v3 endpoint and add a GitHub Actions workflow that restores and builds on windows-latest. It builds Debug only, since Release strong-name signs against a SqlDatabaseBuilder.snk that lives in Azure DevOps rather than the repo. It does not run tests: every fixture under tests/ reads a connection string from AzureSqlServerPath and talks to a live SQL Server.

Breaking change

The minimum .NET Framework target moves from net46 to net462, because net462 is the oldest Framework target SqlClient 6.x ships. .NET Framework support is retained, just not for 4.6 and 4.6.1, both of which left Microsoft support in April 2022. Consumers on net461 and up already resolved against the netstandard2.0 asset. Package version goes to 4.0.0.

Note that 6.x also widens the library dependency footprint, pulling in Azure.Identity, Azure.Core and Microsoft.Extensions.Caching.Memory. That is inherent to modern SqlClient.

Clears CVE-2024-0056 (high) and CVE-2022-41064 (moderate). 2.1.7 stays on
the 2.1.x line and still ships netstandard2.0 and net46 assets, so the
published package's target frameworks are unchanged.

Also retargets the test project from net46;netcoreapp3.1 to net472;net10.0
and updates the test packages. netcoreapp3.1 is out of support and its
targeting packs are gone from current SDKs, and Microsoft.NET.Test.Sdk 18.x
requires net462 or later while xunit.runner.visualstudio 3.x requires
net472, so net46 could not stay. The library itself still targets net46 and
net472 consumes that asset.

Adds a GitHub Actions workflow that restores and compiles the solution.
Tests are not run there: every fixture reads a connection string from the
AzureSqlServerPath environment variable and talks to a live SQL Server.
NuGet.Config pointed at the retired nuget.org v2 endpoint, which modern
NuGet clients cannot restore from; it now uses v3.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Supersedes the 2.1.7 bump in the previous commit. Adding the build workflow
surfaced three more advisories that NuGet Audit reports but Dependabot never
alerted on, all transitive under SqlClient 2.1.x:

  - System.Drawing.Common 4.7.0, critical (GHSA-rxg9-xrhp-64gj), reached via
    System.Runtime.Caching -> System.Configuration.ConfigurationManager ->
    System.Security.Permissions -> System.Windows.Extensions
  - System.IdentityModel.Tokens.Jwt 6.8.0, moderate (GHSA-59j7-ghrg-fj52)
  - Microsoft.IdentityModel.JsonWebTokens 6.8.0, same advisory

6.1.6 removes the cause rather than pinning around it: it replaced
System.Runtime.Caching with Microsoft.Extensions.Caching.Memory, so that
whole chain is gone, and it requires the IdentityModel packages at 7.7.1.

BREAKING CHANGE: the minimum .NET Framework target goes from net46 to net462,
because that is the oldest Framework target SqlClient 6.x ships. Consumers on
net46 or net461 must move to net462 or later; net461 and up already resolved
against the netstandard2.0 asset. .NET Framework 4.6 and 4.6.1 left Microsoft
support in April 2022. Package version goes to 4.0.0 to reflect this.

Only SqlConnection and SqlCommand are used from SqlClient, both unchanged, so
no source edits were needed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Xtrimmer Xtrimmer changed the title fix: Bump Microsoft.Data.SqlClient to 2.1.7 feat!: Bump Microsoft.Data.SqlClient to 6.1.6 Aug 12, 2026
@Xtrimmer
Xtrimmer merged commit 3eb72b0 into master Aug 12, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant