Repository navigation
Remove unused AutoFixture reference from AspNetCore.Test - #565
Open
elinohlsson wants to merge 1 commit into
Open
elinohlsson wants to merge 1 commit into
elinohlsson wants to merge 1 commit into
Conversation
AutoFixture was not used in ActiveLogin.Authentication.BankId.AspNetCore.Test. It pulled in Fare -> NETStandard.Library 1.6.1 -> System.Net.Http 4.3.0, which is flagged as a high severity vulnerability. Removing the reference clears the transitive dependency from all projects in the solution. AutoFixture is still used in ActiveLogin.Authentication.BankId.Api.Test.
There was a problem hiding this comment.
🟢 Approval recommended
The dependency is unused in the affected project, and its removal is isolated and safe.
0 open findings
What changed in this PR
Removes an unused dependency to eliminate a vulnerable transitive package.
Changes:
- Removed the unused
AutoFixturereference. - Retained
AutoFixturein the API test project where it is used.
| File | Description |
|---|---|
test/ActiveLogin.Authentication.BankId.AspNetCore.Test/ActiveLogin.Authentication.BankId.AspNetCore.Test.csproj |
Removes the unused package reference. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Remove unused AutoFixture reference from AspNetCore.Test
Problem
NuGet audit flagged
System.Net.Http4.3.0 as a high severity vulnerability inActiveLogin.Authentication.BankId.AspNetCore.Test. It was a transitive dependency:AutoFixture 4.18.1 is the latest release and still depends on Fare 2.1.1, so upgrading the parent package doesn't fix it.
Fix
AutoFixturewas not used anywhere in the AspNetCore test project, so I removed the package reference. This removes the vulnerable transitive dependency without pinningSystem.Net.Http4.3.4. A pin would also have needed aNU1510suppression, because .NET 10 prunesSystem.Net.Http.Notes
AutoFixtureis still used inActiveLogin.Authentication.BankId.Api.Test, so that reference stays. That project's dependency graph stops atFare, so it doesn't pull inSystem.Net.Http.Api.Testbut not in the AspNetCore test project. Re-adding AutoFixture to the AspNetCore test project could bring the warning back.Verification
dotnet buildof the AspNetCore test project: 0 warnings, 0 errors.dotnet list package --include-transitive --vulnerablefor that project: no vulnerable packages.dotnet nuget why ActiveLogin.Authentication.sln System.Net.Http: no project depends onSystem.Net.Http.I didn't run the full test suite, so CI will do that.
Follow-up (separate PR)
Fail CI on vulnerable packages by turning the NuGet audit warnings (NU1903 and NU1904) into errors.