NuGet vulnerability warnings: Warn in non-Release mode, Error in non-Release mode#17244
NuGet vulnerability warnings: Warn in non-Release mode, Error in non-Release mode#17244JasonElkin merged 19 commits intoumbraco:mainfrom
Conversation
…errored, to change to ignore the four specific Nuget vulnerability warnings in Debug mode (but not Release) as per https://learn.microsoft.com/en-us/nuget/reference/errors-and-warnings/nu1901-nu1904 (NU1901,NU1902,NU1903,NU1904)
|
Hi there @emmagarland, thank you for this contribution! 👍 While we wait for one of the Core Collaborators team to have a look at your work, we wanted to let you know about that we have a checklist for some of the things we will consider during review:
Don't worry if you got something wrong. We like to think of a pull request as the start of a conversation, we're happy to provide guidance on improving your contribution. If you realize that you might want to make some changes then you can do that by adding new commits to the branch you created for this work and pushing new commits. They should then automatically show up as updates to this pull request. Thanks, from your friendly Umbraco GitHub bot 🤖 🙂 |
src/Umbraco.Cms.Persistence.EFCore.SqlServer/Umbraco.Cms.Persistence.EFCore.SqlServer.csproj
Outdated
Show resolved
Hide resolved
…d.props, combine WarningsNotAsErrors and fix minor issues
|
I've slightly changed the way the Testing was as easy as downgrading one on the package versions, for example: And running We might want to change the condition to only emit the error when building a public version (without the |
I had a quick look into this and although Nerdbank.GitVersioning does set the Maybe a better solution is to simply disable the auditing (using |
|
Ah ok, so if that works for the build process that's a cool idea. I'm happy to go with you and the HQ team's preferences on that! It's definitely a good shout to have more urgent behaviour for the more severe warnings. |
|
@ronaldbarendse is there anything else needed for this or can we progress it to be merged? Would that be HQ or Core Collage? Just aware that I didn't want it to get out of date with all the pushes and then have the same issue for everyone again. |
|
Hi there @emmagarland! First of all: A big #H5YR for making an Umbraco related contribution during Hacktoberfest! We are very thankful for the huge amount of PRs submitted, and all the amazing work you've been doing 🥇 Due to the amazing work you and others in the community have been doing, we've had a bit of a hard time keeping up. 😅 While all of the PRs for Hacktoberfest might not have been merged yet, you still qualify for receiving some Umbraco swag, congratulations! 🎉 In the spirit of Hacktoberfest we've prepared some exclusive Umbraco swag for all our contributors - including you! As an alternative choice, you can opt-out of receiving anything and ask us to help improve the planet instead by planting a tree on your behalf. 🌳 Receive your swag or plant a tree! 👈 Please follow this link to fill out and submit the form, before December 25nd, 2024, 23:59:00 UTC. Following this date we'll be sending out all the swag, but please note that it might not reach your doorstep for a few weeks/months, so please bear with us and be patient 🙏 The only thing left to say is thank you so much for participating in Hacktoberfest! We really appreciate the help! Kind regards, |
# Conflicts: # Directory.Build.props # tests/Umbraco.Tests.Common/Builders/Extensions/BuilderExtensions.cs # tests/Umbraco.Tests.Common/Builders/MediaTypeEditingBuilder.cs
Removed unwanted change
Removed unwanted change
|
Hi @ronaldbarendse , I got round to merging All that remains really are a few typos/wording tweaks. Happy to either close this, or just progress with the slight wording changes. Thanks Emma |
|
(update, I've added a couple more updates to reduce more warnings while I'm here) |
There was a problem hiding this comment.
Pull Request Overview
This pull request addresses NuGet vulnerability warnings by configuring projects to treat specific vulnerability warnings (NU1901-NU1904) as warnings in non-Release mode but as errors in Release mode. The PR also includes various formatting fixes and code cleanup across test files.
- Standardizes warning handling for NuGet vulnerabilities across multiple project files
- Fixes method formatting and field naming conventions in test files
- Removes obsolete warning suppressions and cleans up project file formatting
Reviewed Changes
Copilot reviewed 13 out of 14 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| tests/Umbraco.Tests.Common/Builders/MediaTypeEditingBuilder.cs | Formats method parameters across multiple lines |
| tests/Umbraco.Tests.Common/Builders/Extensions/BuilderExtensions.cs | Formats method parameters across multiple lines |
| tests/Umbraco.Tests.Benchmarks/Umbraco.Tests.Benchmarks.csproj | Removes obsolete warning suppressions and adds BOM |
| tests/Umbraco.TestData/Umbraco.TestData.csproj | Removes obsolete warning suppressions |
| tests/Umbraco.TestData/LoadTestController.cs | Refactors static field naming from s_ to _ prefix and modernizes substring usage |
| src/Umbraco.Web.Website/Umbraco.Web.Website.csproj | Updates comment formatting |
| src/Umbraco.Web.Common/Umbraco.Web.Common.csproj | Removes extra whitespace |
| src/Umbraco.Examine.Lucene/Umbraco.Examine.Lucene.csproj | Removes duplicate comment |
| src/Umbraco.Core/Umbraco.Core.csproj | Updates comment formatting |
| src/Umbraco.Cms.Targets/Umbraco.Cms.Targets.csproj | Removes extra whitespace |
| src/Umbraco.Cms.Persistence.Sqlite/Umbraco.Cms.Persistence.Sqlite.csproj | Removes extra whitespace |
| src/Umbraco.Cms.Persistence.SqlServer/Umbraco.Cms.Persistence.SqlServer.csproj | Fixes typo in comment |
| src/Umbraco.Cms.Api.Delivery/Umbraco.Cms.Api.Delivery.csproj | Adds BOM and removes extra whitespace |
|
Thanks @emmagarland 🚀 |

Initial adjustment of the projects with package vulnerabilities that errored due to GHSA-qj66-m88j-hmgj 09/10/24.
Changed to ignore the four specific NuGet vulnerability warnings in Debug mode (but not Release) as per Microsoft docs (
NU1901,NU1902,NU1903,NU1904)Relates to #17235.
Also updated some formatting errors in tests.
Prerequisites
Description
NU1901,NU1902,NU1903,NU1904Next steps
If this approach is confirmed to work, I will add the configuration to all projects in case they get any future vulnerabilities.