Skip to content

fix: bump SSH.NET to 2026.0.0 (route-to-live health check remediation) - #72

Merged
frasermolyneux merged 1 commit into
mainfrom
agents/autonomous-health-check-remediation
Aug 30, 2026
Merged

frasermolyneux merged 1 commit into
mainfrom
agents/autonomous-health-check-remediation

Conversation

@frasermolyneux

Copy link
Copy Markdown
Owner

Summary

Route-to-live health-check remediation: bump SSH.NET 2025.1.0 → 2026.0.0 to clear the NU1903 high-severity advisory (GHSA-q939-rpr3-3284) that was failing build-and-test on every PR based on main (TreatWarningsAsErrors promotes the NuGet audit warning to an error). This restores a green PR-validation pipeline and is the vehicle used to validate the dev deployment end-to-end.

Closes #

Type of change

  • bugfix
  • feature
  • chore / refactor
  • docs
  • infra (Terraform)
  • ci (GitHub Actions / Dependabot)
  • dependencies
  • breaking change

Required reading consulted

  • AGENTS.md (repo brief)
  • .github/copilot-instructions.md (repo orientation)
  • .github-copilot/.github/instructions/personal.working-preferences.instructions.md (always-on rules)
  • Stack-specific instruction files referenced in AGENTS.md

Validation evidence

Build

dotnet build src\XtremeIdiots.Portal.Server.Agent.slnx -c Release
Build succeeded.
    0 Warning(s)
    0 Error(s)

Tests

dotnet test ... --no-build --filter "FullyQualifiedName!~IntegrationTests"
Passed!  - Failed:     0, Passed:   357, Skipped:     0, Total:   357

Format check

dotnet format src\XtremeIdiots.Portal.Server.Agent.slnx --verify-no-changes
EXIT: 0   (no changes)

Other

The deploy-dev label is applied to this PR to validate the dev route-to-live (terraform plan+apply to Development + container build/push/update). See the PR Verify run for the deployment conclusion.

Risk and rollout

  • Blast radius: Development only via the deploy-dev label on this PR. The code change is a single NuGet patch/roll of SSH.NET; the runtime SFTP client (SftpLogTailer, SftpRemoteFileClient) compiles and all unit tests pass against the new version.
  • Auto-deploys on merge? No. Merge to main builds/pushes the image; production deploy is a separate gated path. This PR does not modify workflows or Terraform.
  • Manual steps post-merge: None.
  • Rollback plan: Revert this one-line dependency bump. No infra or contract changes.

Reviewer focus areas

This duplicates the SSH.NET bump that Dependabot PRs #70 and #71 already carry — it exists as a non-Dependabot PR so it can trigger the deploy-dev jobs (those are gated off for dependabot[bot] authors) and validate the dev route-to-live. Merge whichever you prefer; they converge on the same SSH.NET 2026.0.0.

Agent attestation

  • Ran code-review sub-agent; High/Medium findings resolved or justified above in Reviewer focus areas
  • PR body cites each acceptance criterion from the linked issue
  • No client secrets, GUIDs, connection strings, or hard-coded subscription IDs introduced

SSH.NET 2025.1.0 carries GHSA-q939-rpr3-3284 (high). With TreatWarningsAsErrors, the NU1903 audit warning fails build-and-test on every PR based on current main. Bumping to 2026.0.0 restores a green PR-validation pipeline and enables dev-deploy validation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings August 18, 2026 21:08
@frasermolyneux frasermolyneux added the deploy-dev Run dev Terraform plan+apply and deploy the app label Aug 18, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request remediates the route-to-live health-check pipeline failure by updating the SSH.NET NuGet dependency to a non-vulnerable version, clearing the NU1903 advisory that is promoted to an error via TreatWarningsAsErrors.

Changes:

  • Bump SSH.NET from 2025.1.0 to 2026.0.0 in the agent app project.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@frasermolyneux
frasermolyneux marked this pull request as ready for review August 18, 2026 21:09
@github-actions

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

License Issues

src/XtremeIdiots.Portal.Server.Agent.App/XtremeIdiots.Portal.Server.Agent.App.csproj

PackageVersionLicenseIssue Type
SSH.NET2026.0.0NullUnknown License

OpenSSF Scorecard

PackageVersionScoreDetails
nuget/SSH.NET 2026.0.0 UnknownUnknown

Scanned Files

  • src/XtremeIdiots.Portal.Server.Agent.App/XtremeIdiots.Portal.Server.Agent.App.csproj

@sonarqubecloud

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown

🏗️ Terraform Plan & Apply

🌍 Environment: dev

✅ Plan

Count
➕ Add 8
📋 Resource Details
Action Resource
➕ Create azurerm_container_app.app
➕ Create azurerm_container_app_environment.env
➕ Create azurerm_monitor_activity_log_alert.rg_resource_health
➕ Create azurerm_role_assignment.app_to_storage
➕ Create azurerm_storage_account.agent_storage
➕ Create azurerm_storage_container.server_locks
➕ Create azurerm_storage_container.tailer_offsets
➕ Create random_id.environment_id

@frasermolyneux
frasermolyneux merged commit 67d588b into main Aug 30, 2026
34 checks passed
@frasermolyneux
frasermolyneux deleted the agents/autonomous-health-check-remediation branch August 30, 2026 13:53

This branch was previously deployed

1 inactive deployment
Development — 80debbb3 Deployed Aug 18, 2026 by frasermolyneux via container-deploy-dev #266
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

deploy-dev Run dev Terraform plan+apply and deploy the app

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants