Skip to content

Bump Scriban to 7.4.0 to fix known vulnerabilities - #288

Open
yvanlo wants to merge 2 commits into
martinothamar:mainfrom
yvanlo:deps/bump-scriban
Open

yvanlo wants to merge 2 commits into
martinothamar:mainfrom
yvanlo:deps/bump-scriban

Conversation

@yvanlo

@yvanlo yvanlo commented Sep 21, 2026

Copy link
Copy Markdown

Scriban 7.0.0 has known advisories, reported as NuGet audit warnings when building the source generator:

All are fixed in 7.2.2+. This bumps Scriban to the latest version, 7.4.0.

Mediator only renders its own embedded templates, so the practical risk is low, but the audit warnings go away.

Build fix

Since 7.2, the Scriban source uses trimming attributes (DynamicallyAccessedMembers, UnconditionalSuppressMessage, RequiresUnreferencedCode, ...) that don't exist on netstandard2.0. PolySharp doesn't generate these by default, so I enabled PolySharpIncludeRuntimeSupportedAttributes.

Testing

  • dotnet build of the solution: 0 errors
  • dotnet test: Mediator.Tests, Mediator.Telemetry.Tests and Mediator.MemAllocationTests pass
  • Mediator.SourceGenerator.Tests: 187/190 pass. The SampleTests go from 8 failures on main to 3 on this branch (on my machine). The 3 remaining failures are NuGet audit warnings from other sample packages (Microsoft.OpenApi 2.0.0, OpenTelemetry.* 1.15.0), not related to this change.

Newer Scriban source uses trimming attributes (DynamicallyAccessedMembers etc.) that don't exist on netstandard2.0.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant