fix(security): patch vulnerable NuGet dependencies flagged by CI gate
The new dependency scan correctly failed on real advisories. Bump MailKit 4.13.0->4.17.0 (clears MailKit+MimeKit moderates) and add transitive security pins for the .NET 8.0.0 High-severity advisories: System.Text.Json 8.0.6, Microsoft.Extensions.Caching.Memory 8.0.1 (with DependencyInjection.Abstractions 8.0.2), System.Security.Cryptography.Xml 8.0.3. Verified locally: clean vuln scan, Release build OK, all 39 tests pass. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -5,6 +5,12 @@ All notable changes to InboxIntel are documented here. Format follows
|
||||
[Semantic Versioning](https://semver.org/). See [docs/WORKFLOW.md](docs/WORKFLOW.md).
|
||||
|
||||
## [Unreleased]
|
||||
### Security
|
||||
- Patched all High/Moderate NuGet advisories the new dependency gate surfaced:
|
||||
`System.Text.Json` 8.0.0→8.0.6, `Microsoft.Extensions.Caching.Memory` 8.0.0→8.0.1
|
||||
(+ `DependencyInjection.Abstractions`→8.0.2), `System.Security.Cryptography.Xml`
|
||||
8.0.1→8.0.3 (transitive pins), and `MailKit`/`MimeKit` 4.13.0→4.17.0.
|
||||
|
||||
### Added
|
||||
- CI/CD pipeline (`.gitea/workflows/`): `security` (gitleaks secret scan + NuGet/npm
|
||||
vulnerability gate), `deploy-staging` (auto-redeploy local staging on `develop`),
|
||||
|
||||
Reference in New Issue
Block a user