Skip to content

Remove unused AutoFixture reference from AspNetCore.Test - #565

Open
elinohlsson wants to merge 1 commit into
mainfrom
feature/nuget-upgrade
Open

elinohlsson wants to merge 1 commit into
mainfrom
feature/nuget-upgrade

Conversation

@elinohlsson

Copy link
Copy Markdown
Contributor

Remove unused AutoFixture reference from AspNetCore.Test

Problem

NuGet audit flagged System.Net.Http 4.3.0 as a high severity vulnerability in ActiveLogin.Authentication.BankId.AspNetCore.Test. It was a transitive dependency:

AutoFixture 4.18.1 → Fare 2.1.1 → NETStandard.Library 1.6.1 → System.Net.Http 4.3.0

AutoFixture 4.18.1 is the latest release and still depends on Fare 2.1.1, so upgrading the parent package doesn't fix it.

Fix

AutoFixture was not used anywhere in the AspNetCore test project, so I removed the package reference. This removes the vulnerable transitive dependency without pinning System.Net.Http 4.3.4. A pin would also have needed a NU1510 suppression, because .NET 10 prunes System.Net.Http.

Notes

  • AutoFixture is still used in ActiveLogin.Authentication.BankId.Api.Test, so that reference stays. That project's dependency graph stops at Fare, so it doesn't pull in System.Net.Http.
  • It's not clear why the chain was pruned in Api.Test but not in the AspNetCore test project. Re-adding AutoFixture to the AspNetCore test project could bring the warning back.

Verification

  • dotnet build of the AspNetCore test project: 0 warnings, 0 errors.
  • dotnet list package --include-transitive --vulnerable for that project: no vulnerable packages.
  • dotnet nuget why ActiveLogin.Authentication.sln System.Net.Http: no project depends on System.Net.Http.

I didn't run the full test suite, so CI will do that.

Follow-up (separate PR)

Fail CI on vulnerable packages by turning the NuGet audit warnings (NU1903 and NU1904) into errors.

AutoFixture was not used in ActiveLogin.Authentication.BankId.AspNetCore.Test.
It pulled in Fare -> NETStandard.Library 1.6.1 -> System.Net.Http 4.3.0,
which is flagged as a high severity vulnerability.

Removing the reference clears the transitive dependency from all projects
in the solution. AutoFixture is still used in
ActiveLogin.Authentication.BankId.Api.Test.
@elinohlsson
elinohlsson marked this pull request as ready for review October 9, 2026 15:19
@elinohlsson
elinohlsson requested a balanced review from Copilot October 9, 2026 15:19

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The dependency is unused in the affected project, and its removal is isolated and safe.

0 open findings

What changed in this PR

Removes an unused dependency to eliminate a vulnerable transitive package.

Changes:

  • Removed the unused AutoFixture reference.
  • Retained AutoFixture in the API test project where it is used.
File Description
test/​ActiveLogin.Authentication.BankId.AspNetCore.Test/​ActiveLogin.Authentication.BankId.AspNetCore.Test.csproj Removes the unused package reference.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants