Skip to content

fix(worker): Bump ImageSharp to 4.1.2 to clear five security advisories - #203

Merged
bitbiter-dev merged 3 commits into
masterfrom
fix/190-imagesharp-4
Oct 9, 2026
Merged

bitbiter-dev merged 3 commits into
masterfrom
fix/190-imagesharp-4

Conversation

@bitbiter-dev

@bitbiter-dev bitbiter-dev commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Refs #190. Unblocks #112, #200, #201, #202.

Why

Five advisories against ImageSharp 3.1.12 are patched only in 4.1.2:

Because NuGetAudit runs at moderate with warnings treated as errors, master does not currently build. This bumps ImageSharp on its own, so the fix doesn't have to wait for #189's test-platform migration.

Changes

  • SixLabors.ImageSharp 3.1.12 → 4.1.2, and Blurhash.ImageSharp 3.0.0 → 4.1.1, which pins ImageSharp 4. No code changes were needed.
  • Licence wiring. ImageSharp 4 checks the Six Labors licence at build time. A missing licence is a warning in Debug and an error in Release. The licence is a credential and is never committed:
    • Local: sixlabors.lic sits at the repo root, is gitignored, and Directory.Build.props points SixLaborsLicenseFile at it. The package only searches downward from each project, so it would not find the root file without this.
    • Override: setting SixLaborsLicenseKey (as an MSBuild property or env var) takes precedence over the file.
    • Worker image: the key arrives through a BuildKit secret mount (id=sixlabors_license), not a build arg, so it never ends up in a layer or in the image history.
    • CI: the docker job passes secrets.SIXLABORS_LICENSE_KEY to build-push-action. Build & test run in Debug, so they don't need the key.

Before merging

  • Add the SIXLABORS_LICENSE_KEY repository secret for Actions.
  • Add the same secret for Dependabot, or the Docker job will fail on Dependabot PRs.
  • Fork PRs get no secrets, so their Worker image build will fail. That's expected.

Verification

  • dotnet build src/ passes in Debug and Release with 0 warnings and 0 errors.
  • Release build of the Worker:
    • with the licence file: passes
    • without the file: fails with "No Six Labors license found"
    • with no file and the SixLaborsLicenseKey env var set: passes
  • Tests: 639/639 pass, including under NZDT.
  • Not tested locally: the Docker image build, because no daemon was available. The CI docker job will be the first real check.

Also: timezone-dependent test

PersistenceMiddlewareTests.InvokeAsync_WithNullDateCaptured_FallsBackToFileLastWriteTimeAsync set the file time to 12:00 UTC, but the fallback reads LastWriteTime in host-local time. East of UTC+12 the asserted day was off by one, and master fails the same way. The fixture time is now expressed in local time. Production behaviour is unchanged. The test passes under UTC, Pacific/Auckland, Pacific/Kiritimati (UTC+14), Etc/GMT+12 (UTC−12) and Europe/Zurich.

🤖 Generated with Claude Code

bitbiter-dev and others added 3 commits October 10, 2026 11:49
ImageSharp 3.1.12 carries GHSA-j3p4-wp97-rph4, GHSA-j9gm-c75j-xc9q,
GHSA-jjfr-hcj7-qf5w (high) and GHSA-gwg2-r3hj-4w44, GHSA-wmxv-xphr-5c9g
(moderate), all patched only in 4.1.2. With NuGetAudit at moderate and
warnings as errors, master no longer builds. Blurhash.ImageSharp moves to
4.1.1 because it pins ImageSharp 4.

ImageSharp 4 validates a Six Labors licence at build time: Debug warns,
Release fails. The licence is a credential and is never committed:
- locally, a gitignored sixlabors.lic at the repo root is wired in via
  SixLaborsLicenseFile (the package's own search only looks downward
  from each project, so it cannot find the root file);
- an SixLaborsLicenseKey property or env var takes precedence;
- the Worker image receives it as a BuildKit secret mount, not a build
  arg, so it never lands in a layer or the image history; CI passes
  secrets.SIXLABORS_LICENSE_KEY to build-push-action.

Refs #190

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The fixture set the file time to 12:00 UTC, but the fallback reads
LastWriteTime in host-local time, so the asserted day was off by one
east of UTC+12 (e.g. Pacific/Auckland in NZDT). Express the fixture
time in local time instead; production behaviour is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@bitbiter-dev
bitbiter-dev merged commit 7ce1912 into master Oct 9, 2026
7 checks passed
@bitbiter-dev
bitbiter-dev deleted the fix/190-imagesharp-4 branch October 9, 2026 23:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant