fix(security): patch vulnerable NuGet dependencies flagged by CI gate
CI / backend (pull_request) Successful in 1m13s
CI / frontend (pull_request) Successful in 29s
Security / secrets (pull_request) Successful in 6s
Security / dependencies (pull_request) Successful in 1m13s

The new dependency scan correctly failed on real advisories. Bump MailKit
4.13.0->4.17.0 (clears MailKit+MimeKit moderates) and add transitive security
pins for the .NET 8.0.0 High-severity advisories: System.Text.Json 8.0.6,
Microsoft.Extensions.Caching.Memory 8.0.1 (with DependencyInjection.Abstractions
8.0.2), System.Security.Cryptography.Xml 8.0.3. Verified locally: clean vuln
scan, Release build OK, all 39 tests pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
cesnimda
2026-07-01 11:38:08 +02:00
parent 98e94a8163
commit e981c63a4d
3 changed files with 17 additions and 2 deletions
+6
View File
@@ -5,6 +5,12 @@ All notable changes to InboxIntel are documented here. Format follows
[Semantic Versioning](https://semver.org/). See [docs/WORKFLOW.md](docs/WORKFLOW.md).
## [Unreleased]
### Security
- Patched all High/Moderate NuGet advisories the new dependency gate surfaced:
`System.Text.Json` 8.0.0→8.0.6, `Microsoft.Extensions.Caching.Memory` 8.0.0→8.0.1
(+ `DependencyInjection.Abstractions`→8.0.2), `System.Security.Cryptography.Xml`
8.0.1→8.0.3 (transitive pins), and `MailKit`/`MimeKit` 4.13.0→4.17.0.
### Added
- CI/CD pipeline (`.gitea/workflows/`): `security` (gitleaks secret scan + NuGet/npm
vulnerability gate), `deploy-staging` (auto-redeploy local staging on `develop`),