Suppress SharpCompress NU1902 audit warning to unblock release build

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Done
    • Priority: Critical - P2
    • 3.8.1
    • Affects Version/s: None
    • Component/s: None
    • None
    • None
    • Dotnet Drivers
    • Not Needed
    • None
    • None
    • None
    • None
    • None
    • None

      Following the Snappier security upgrade in CSHARP-6034, the release build for 3.8.1 is failing because of a separate transitive-dependency advisory:

      The driver does not exercise the vulnerable code path (IArchive.WriteToDirectory()); SharpCompress is only used for in-memory ZLib stream compression of MongoDB wire-protocol messages. However, TreatWarningsAsErrors=true in the build props converts the NU1902 warning into a build error and breaks the release pipeline.

            Assignee:
            Adelin Mbida Owona
            Reporter:
            Adelin Mbida Owona
            None
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: