Skip to content

Align the Part 4 Docker-free SQLite pin with dependency policy #655

Description

@jongalloway

Issue type

dependencies

Requested priority

P3 - Polish, minor documentation, screenshots, or future improvement

Workshop area

Part 4 - AI Web Chat Template

Summary

The Docker-free Part 4 instructions pin SQLitePCLRaw.bundle_e_sqlite3 3.0.4, while docs/instructor/DEPENDENCY_POLICY.md identifies 3.0.5 as the current verified security override for that same path.

Both files are intended to be authoritative in their respective contexts, so they should name the same tested version.

Attendee or instructor impact

The current 3.0.4 path restored, built, started, returned HTTP 200, and produced no vulnerability finding during the September 13 test. This is therefore not a reproduced runtime or security failure, but it leaves maintainers and instructors with conflicting guidance about the supported security override.

Reproduction or proposed change

Compare the Docker-free package command in:

Part 04 - AI Web Chat Template/README.md

with the protected-dependency entry in:

docs/instructor/DEPENDENCY_POLICY.md

The README uses:

dotnet add GenAiLab package SQLitePCLRaw.bundle_e_sqlite3 --version 3.0.4

The policy identifies 3.0.5 as the verified override.

Proposed change:

  1. Determine whether 3.0.5 is the intended workshop baseline after the separate Aspire 13.4.6 work lands.
  2. If yes, update the Part 4 command and explanation to 3.0.5.
  3. If 3.0.4 is intentionally retained for template compatibility, update the dependency policy with that rationale and verification evidence.
  4. Check whether the direct override is still necessary by inspecting the resolved transitive graph; do not remove it solely because the build succeeds.

Expected outcome

The attendee README and dependency policy identify one tested SQLitePCLRaw version and explain why the direct reference is required.

Validation

  • Scaffold the Docker-free Part 4 variant from the current template.
  • Apply the selected SQLitePCLRaw version.
  • Build in Release with zero warnings.
  • Start the application and confirm HTTP 200.
  • Exercise local-vector ingestion/search.
  • Run dotnet list package --vulnerable --include-transitive.
  • Confirm the README and dependency policy contain the same version.

Dependencies and related issues

Coordinate with the separate PR changing the workshop Aspire baseline to 13.4.6, because its dependency graph may affect which direct overrides are required.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-decisionScope or product direction must be decided before implementation

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions