Skip to content

Update AngleSharp to latest - #67898

Merged
ilonatommy merged 5 commits into
mainfrom
dev/ygerges/anglesharp
Jul 20, 2026
Merged

Update AngleSharp to latest#67898
ilonatommy merged 5 commits into
mainfrom
dev/ygerges/anglesharp

Conversation

@Youssef1313

@Youssef1313 Youssef1313 commented Jul 20, 2026

Copy link
Copy Markdown
Member

Fixes #67902.

Copilot AI review requested due to automatic review settings July 20, 2026 07:42
@Youssef1313
Youssef1313 requested review from a team and wtgodbe as code owners July 20, 2026 07:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the centrally-managed AngleSharp dependency version in the ASP.NET Core repo via eng/Versions.props.

Changes:

  • Bump AngleSharpVersion from 0.9.9 to 1.5.2.

Comment thread eng/Versions.props
<!-- 3rd party dependencies -->
<AzureIdentityVersion>1.11.4</AzureIdentityVersion>
<AngleSharpVersion>0.9.9</AngleSharpVersion>
<AngleSharpVersion>1.5.2</AngleSharpVersion>

@ilonatommy ilonatommy left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Advisory says >1.5.0 so it should fix the error. Let's hope this bump won't break the compilation of other projects.

@Youssef1313
Youssef1313 requested a review from a team as a code owner July 20, 2026 09:08
@ilonatommy ilonatommy added the area-infrastructure Includes: MSBuild projects/targets, build scripts, CI, Installers and shared framework label Jul 20, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Hey @dotnet/aspnet-build, looks like this PR is something you want to take a look at.

@Youssef1313
Youssef1313 requested a review from halter73 as a code owner July 20, 2026 09:16

@ilonatommy ilonatommy left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Refresh.

@ilonatommy
ilonatommy enabled auto-merge (squash) July 20, 2026 09:28
@Youssef1313

Youssef1313 commented Jul 20, 2026

Copy link
Copy Markdown
Member Author

/ba-g Build already broken (on main). Helix stuck is probably flakiness or infra.

@ilonatommy
ilonatommy merged commit fc4e6e0 into main Jul 20, 2026
24 of 26 checks passed
@ilonatommy
ilonatommy deleted the dev/ygerges/anglesharp branch July 20, 2026 12:48
@dotnet-milestone-bot dotnet-milestone-bot Bot added this to the 11.0-preview7 milestone Jul 21, 2026
wtgodbe pushed a commit that referenced this pull request Jul 27, 2026
…WebSite

Ports #67898 (AngleSharp 0.9.9 -> 1.5.2, fixing
GHSA-pgww-w46g-26qg) and the NoWarn NU1903/NU1904 change from
#67642 to unblock the NuGet audit failures on this
codeflow PR:
- NU1902 (AngleSharp 0.9.9) in Mvc.FunctionalTests, Identity.Test,
  Identity.FunctionalTests, AuthSamples.FunctionalTests
- NU1903 (Newtonsoft.Json 11.0.2) and NU1904 (Kestrel.Core 2.2.0) in
  InProcessNewShimWebSite (a forward-compat test asset intentionally
  pinned to old package versions)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
wtgodbe pushed a commit that referenced this pull request Jul 28, 2026
* Backflow from https://github.com/dotnet/dotnet / e0c9b3f build 324500

Diff: https://github.com/dotnet/dotnet/compare/4c953a1fd4fe2a8952826ad3a2d69dce9042ee32..e0c9b3f934e7b97b360f4ce3692ab45b9634ae1d

From: dotnet/dotnet@4c953a1
To: dotnet/dotnet@e0c9b3f

[[ commit created by automation ]]

* Update dependencies from build 324500
Updated Dependencies:
Microsoft.NET.Runtime.WebAssembly.Sdk, Microsoft.NET.Runtime.MonoAOTCompiler.Task, dotnet-ef, Microsoft.Bcl.AsyncInterfaces, Microsoft.Bcl.TimeProvider, Microsoft.EntityFrameworkCore, Microsoft.EntityFrameworkCore.Design, Microsoft.EntityFrameworkCore.InMemory, Microsoft.EntityFrameworkCore.Relational, Microsoft.EntityFrameworkCore.Sqlite, Microsoft.EntityFrameworkCore.SqlServer, Microsoft.EntityFrameworkCore.Tools, Microsoft.Extensions.Caching.Abstractions, Microsoft.Extensions.Caching.Memory, Microsoft.Extensions.Configuration, Microsoft.Extensions.Configuration.Abstractions, Microsoft.Extensions.Configuration.Binder, Microsoft.Extensions.Configuration.CommandLine, Microsoft.Extensions.Configuration.EnvironmentVariables, Microsoft.Extensions.Configuration.FileExtensions, Microsoft.Extensions.Configuration.Ini, Microsoft.Extensions.Configuration.Json, Microsoft.Extensions.Configuration.UserSecrets, Microsoft.Extensions.Configuration.Xml, Microsoft.Extensions.DependencyInjection, Microsoft.Extensions.DependencyInjection.Abstractions, Microsoft.Extensions.DependencyModel, Microsoft.Extensions.Diagnostics, Microsoft.Extensions.Diagnostics.Abstractions, Microsoft.Extensions.FileProviders.Abstractions, Microsoft.Extensions.FileProviders.Composite, Microsoft.Extensions.FileProviders.Physical, Microsoft.Extensions.FileSystemGlobbing, Microsoft.Extensions.Hosting, Microsoft.Extensions.Hosting.Abstractions, Microsoft.Extensions.Http, Microsoft.Extensions.Logging, Microsoft.Extensions.Logging.Abstractions, Microsoft.Extensions.Logging.Configuration, Microsoft.Extensions.Logging.Console, Microsoft.Extensions.Logging.Debug, Microsoft.Extensions.Logging.EventLog, Microsoft.Extensions.Logging.EventSource, Microsoft.Extensions.Logging.TraceSource, Microsoft.Extensions.Options, Microsoft.Extensions.Options.ConfigurationExtensions, Microsoft.Extensions.Options.DataAnnotations, Microsoft.Extensions.Primitives, Microsoft.NETCore.App.Ref, System.Collections.Immutable, System.Composition, System.Configuration.ConfigurationManager, System.Diagnostics.DiagnosticSource, System.Diagnostics.EventLog, System.Diagnostics.PerformanceCounter, System.DirectoryServices.Protocols, System.Formats.Asn1, System.Formats.Cbor, System.IO.Hashing, System.IO.Pipelines, System.Memory.Data, System.Net.Http.Json, System.Net.Http.WinHttpHandler, System.Net.ServerSentEvents, System.Numerics.Tensors, System.Reflection.Metadata, System.Resources.Extensions, System.Runtime.Caching, System.Security.Cryptography.Pkcs, System.Security.Cryptography.Xml, System.Security.Permissions, System.ServiceProcess.ServiceController, System.Text.Encodings.Web, System.Text.Json, System.Threading.AccessControl, System.Threading.Channels, System.Threading.RateLimiting (Version 10.0.10 -> 10.0.12)
Microsoft.NETCore.BrowserDebugHost.Transport, Microsoft.Extensions.HostFactoryResolver.Sources, Microsoft.Internal.Runtime.AspNetCore.Transport, Microsoft.NETCore.Platforms (Version 10.0.10-servicing.26359.121 -> 10.0.12-servicing.26376.103)
Microsoft.DotNet.Arcade.Sdk, Microsoft.DotNet.Build.Tasks.Archives, Microsoft.DotNet.Build.Tasks.Installers, Microsoft.DotNet.Build.Tasks.Templating, Microsoft.DotNet.Helix.Sdk, Microsoft.DotNet.RemoteExecutor, Microsoft.DotNet.SharedFramework.Sdk (Version 10.0.0-beta.26359.121 -> 10.0.0-beta.26376.103)
Microsoft.Web.Xdt (Version 3.2.10 -> 3.2.12)
NuGet.Frameworks, NuGet.Packaging, NuGet.Versioning (Version 7.0.3-rc.36021 -> 7.0.3-rc.37703)
[[ commit created by automation ]]

* Bump AngleSharp to 1.5.2 and disable NuGet audit for InProcessNewShimWebSite

Ports #67898 (AngleSharp 0.9.9 -> 1.5.2, fixing
GHSA-pgww-w46g-26qg) and the NoWarn NU1903/NU1904 change from
#67642 to unblock the NuGet audit failures on this
codeflow PR:
- NU1902 (AngleSharp 0.9.9) in Mvc.FunctionalTests, Identity.Test,
  Identity.FunctionalTests, AuthSamples.FunctionalTests
- NU1903 (Newtonsoft.Json 11.0.2) and NU1904 (Kestrel.Core 2.2.0) in
  InProcessNewShimWebSite (a forward-compat test asset intentionally
  pinned to old package versions)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Disable NuGet audit NU1903 for InteropClient test project

Ports the remaining piece of #67642: InteropClient.csproj
transitively pulls Newtonsoft.Json 12.0.3 via Grpc.Auth, tripping
NU1903 (GHSA-5crp-9r3c-p9vr). This is unrelated to the central
NewtonsoftJsonVersion (already 13.0.3, above the 13.0.1 patched
threshold) bumped on main in #66334; that bump does
not touch this transitively-pinned copy. Suppress the same way main
did, since this is a test-only project.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: dotnet-maestro[bot] <dotnet-maestro[bot]@users.noreply.github.com>
Co-authored-by: Will Godbe <willgodbe@Wills-MacBook-Pro.local>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-infrastructure Includes: MSBuild projects/targets, build scripts, CI, Installers and shared framework

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Failed to restore dogfooding tests due to error NU1902: Package 'AngleSharp' 0.9.9 has a known moderate severity vulnerability

4 participants