Skip to content

Bump Sarif.Driver from 4.6.0 to 5.7.0 - #1227

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/nuget/src/Sarif.Driver-5.7.0
Open

dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/nuget/src/Sarif.Driver-5.7.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Updated Sarif.Driver from 4.6.0 to 5.7.0.

Release notes

Sourced from Sarif.Driver's releases.

5.6.0

v5.6.0 Sdk | Driver | Converters | Multitool | Multitool Library

  • BUG: ArtifactLocation.TryReconstructAbsoluteUri returns false (leaving resolvedUri null) when a relative uri's ../ segments escape the originalUriBaseIds base it resolves through, so enrichment no longer reads files outside a declared base.
  • BUG: MultithreadedAnalyzeCommandBase merges per-target RuntimeErrors into the global context under a lock, so concurrent scan workers no longer lose each other's flags.
  • NEW: MultithreadedAnalyzeCommandBase.RunAsync analyzes without blocking the caller, dispatching to new async virtuals that hold the work; Run keeps its signature and dispatches to their synchronous counterparts, so existing subclasses are unaffected.

4.6.5

v4.6.5 Sdk | Driver | Converters | Multitool | Multitool Library

  • BUG: Fix AccessViolationException in EnumeratedArtifact.RetrieveDataFromStream when the caller-provided stream's Seek re-enters native code (e.g. ASP.NET WebAPI's SeekableBufferedRequestStream over IIS's HttpBufferlessInputStream). Always rewind via PeekableStream instead of trusting Stream.CanSeek.

4.6.4

v4.6.4 Sdk | Driver | Converters | Multitool | Multitool Library

  • BUGFIX: Drop the missing-partialFingerprints check from BaseProvideRequiredResultProperties (Base1015), which removes the firing for ADO1015/ADO1017 and GH1015/GH1017. Both Advanced Security for Azure DevOps and GitHub code scanning compute partialFingerprints automatically when omitted, so the error-level "this property is required by the {service} service" message was misleading. See GHAZDO third-party SARIF docs (Sprint 245 ruleId inclusion, Sprint 255 advancedsecurity.publish.allowmissingpartialfingerprints) and GitHub code scanning SARIF support — Fingerprint generation. AI producers are already advised against persisting fingerprints by AI2011.
  • BRK: Rename Microsoft.CodeAnalysis.Sarif.Multitool.OptionsInterpretter (and its test class OptionsInterpretterTests) to OptionsInterpreter / OptionsInterpreterTests (single t). External callers of Sarif.Multitool.Library constructing new OptionsInterpretter(...) must update to new OptionsInterpreter(...).
  • NEW: Add partition multitool verb that splits one SARIF log into many by strategy (PerRule (default), PerRunPerRule, PerRun, PerResult, PerRunPerTarget, PerRunPerTargetPerRule, PerIndexList). Wraps SarifPartitioner.Partition, so each output gets its tool.driver.rules and run.artifacts pruned to only what the partition references.
  • NEW: Add SplittingStrategy.PerIndexList plus the --indices mini-language for explicit per-result bucket assignment: <runId>:<r1>,<r2>;<runId>:...|<bucket>..., with bare-int shorthand for run 0 and SARIF URL fallback (sarif:/runs/X/results/Y, §3.10.3). Optional --spillover-bucket NAME captures uncovered results; --strict-coverage errors on uncovered results. Duplicate or out-of-range addresses error.
  • NEW: Add public SDK helper Microsoft.CodeAnalysis.Sarif.Writers.PartitionFunctions (ForStrategy, ForIndexList, ParseIndexSpec, ResultAddress) to centralize partition-key derivation across SDK consumers.
  • BUG: Fix System.ArgumentException: Illegal characters in path. thrown from MultithreadedAnalyzeCommandBase.IsOpcArtifact on .NET Framework when an artifact's URI yields a file path containing characters illegal in a Windows path (e.g., the ? of a URI query string, or |, <, >, "). The path is now sanitized via PathExtensions.ReplaceInvalidCharInFileName before being passed to Path.GetExtension.
  • BUG: Fix InvalidOperationException: Collection was modified thrown from Newtonsoft.Json.JsonSerializerInternalWriter.SerializeDictionary inside SarifLogger.Dispose on .NET Framework when SarifRewritingVisitor.VisitReportingDescriptor ran concurrently with serialization on a peer logger that shared the same ReportingDescriptor instance. The visitor now builds a new MessageStrings dictionary and assigns the field atomically, so any concurrent reader sees a stable dictionary that nobody is mutating.

4.6.3

v4.6.3 Sdk | Driver | Converters | Multitool | Multitool Library

  • BRK: Renumber AI validation rules for RFC 2119 compliance (AI1xxx = MUST/SHALL error; AI2xxx = SHOULD warning/note). AI2006 → AI1005, AI1007 → AI2014. The AI3xxx series is eliminated.
  • NEW: Add AI1010.EvidenceBackingResolvable (error) — every sarif: URI in ai/evidence[].backing SHALL resolve to an element within the log file (§3.10.3).
  • NEW: Add AI1011.RedactedRunMarker (error) — ai/redacted SHALL be true or absent (never false); when true, run.redactionTokens SHALL be non-empty; ai/fullLogLocation SHALL NOT appear unless ai/redacted is true.
  • NEW: Add AI1012.ProvideRuleSubId (error) — AI-generated results MUST carry a hierarchical sub-component on result.ruleId beyond the base reportingDescriptor.id.
  • NEW: Add AI1013.NotificationAssociatedRuleResolvable (error) — if notification.associatedRule is present, it SHALL resolve to a valid rule in tool.driver.rules[] or an extension's rules[].
  • NEW: Add AI1014.ExecutionNotificationPlacement (error) — AI/EXEC/* descriptors SHALL appear only in toolExecutionNotifications; AI/CFG/* descriptors SHALL appear only in toolConfigurationNotifications.
  • NEW: Add AI2015.ProvideAttackerPosition (warning) — each result SHOULD declare ai/attackerPosition. Follows the all-or-nothing pattern.
  • NEW: Add AI2016.EvidenceBackingConsistency (warning) — an ai/evidence[] entry with strength: "demonstrated" SHOULD carry non-empty backing.
  • NEW: Add AI2017.ProvideNotificationDescriptor (warning) — every notification SHOULD have a descriptor that resolves to a reportingDescriptor in tool.driver.notifications[].
  • NEW: Add AI2018.ProvideExecutionSignalArtifact (note) — AI/EXEC/ALAS-SIGNAL notifications SHOULD include a locations[] entry referencing a valid artifact with roles containing "attachment".
  • NEW: Add AI2019.ProvideNotificationTimestamp (note) — notifications SHOULD include timeUtc for execution timeline reconstruction.

4.6.2

v4.6.2 Sdk | Driver | Converters | Multitool | Multitool Library

  • NEW: Add AI1003.ProvideRequiredRegionProperties validation rule — error when result locations lack a region or required region properties. Mirrors SARIF2017 at error level for AI profile.
  • NEW: Add AI1004.ProvideVersionControlProvenance validation rule — error when run.versionControlProvenance is missing or empty. Ensures AI findings are traceable to source control.
  • NEW: Add AI2006.ProvideMessageMarkdown validation rule — error when AI-generated findings do not include message.markdown.
  • NEW: Add AI1007.ProvideExploitability validation rule — warns when result.properties["ai/exploitability"] is missing or contains an unrecognized value (valid: demonstrated, poc, theoretical). Follows the suppressions pattern (§3.27.23): exploitability must be present on all results or absent from all results; mixed presence is flagged as a data quality error.
  • NEW: Add AI1012.ProvideAIHandoff validation rule — notes when run.properties["ai/handoff"] is missing or empty. This property is intended to provide human-readable handoff instructions for triaging and acting on AI-generated findings.
  • NEW: Add SARIF2017.ProvideRequiredRegionProperties validation rule — warns when result locations lack a region or startLine. Fires in standard profile only (--rule-kind Sarif).
  • NEW: Add RuleKind.AI to SARIF2010.ProvideCodeSnippets and SARIF2011.ProvideContextRegion so these rules fire under --rule-kind AI with no configuration file needed.
  • DEL: Remove policies/ai.config.xml — AI validation now works zero-config via --rule-kind AI.

4.6.1

v4.6.1 Sdk | Driver | Converters | Multitool | Multitool Library

  • NEW: Add health check query parameter support for --post-uri validation. The driver now appends ?healthcheck=true to POST URIs during validation and accepts HTTP 202 (Accepted), or 422 (Unprocessable Entity) as valid responses. This provides better support for endpoints that implement health check functionality while maintaining backwards compatibility with servers that return 422 for empty payloads.
  • NEW: SarifLogger.AnalyzingTarget now optionally emits an explicit artifacts table entry (with AnalysisTarget role) for every scan target when OptionallyEmittedData.AnalysisTargets is set via --insert.

Commits viewable in compare view.

@dependabot dependabot Bot added .NET Pull requests that update .net code dependencies Pull requests that update a dependency file labels Sep 16, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 16, 2026 02:57
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file .NET Pull requests that update .net code labels Sep 16, 2026
@dependabot
dependabot Bot force-pushed the dependabot/nuget/src/Sarif.Driver-5.7.0 branch 4 times, most recently from 9f4f799 to 927132a Compare September 16, 2026 20:41
---
updated-dependencies:
- dependency-name: Sarif.Driver
  dependency-version: 5.7.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/nuget/src/Sarif.Driver-5.7.0 branch from 927132a to 088c17f Compare September 16, 2026 21:34
Explicitly request SHA-1 and SHA-256 when hash insertion is enabled so the Sarif.Driver 5 default change does not break BinSkim's existing --hashes contract.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 2779f142-ce84-4a8d-ba83-c0fb814808a7

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Two moderate dependency and logger-cache issues remain unresolved.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Updates Sarif.Driver to 5.7.0 while preserving SHA-1 and SHA-256 hash output.

Changes:

  • Bumps the centrally managed Sarif.Driver version.
  • Configures explicit SHA-1 and SHA-256 hashing.
File summaries
File Summary
src/Directory.Packages.props Updates Sarif.Driver; the BinaryParsers nuspec dependency also requires updating.
src/BinSkim.Driver/MultithreadedAnalyzeCommand.cs Enables dual-hash output; global logger cache setup requires adjustment for analysis-target artifacts.
Review details

Suppressed comments (1)

src/BinSkim.Driver/MultithreadedAnalyzeCommand.cs:307

  • This cache is installed only on the per-target CachingLogger, but Sarif.Driver 5.7 invokes the global logger's AnalyzingTarget callback before AnalyzeTarget runs. SarifLogger creates AnalysisTarget artifacts in that earlier callback using its existing default SHA-256 cache, so a run requesting AnalysisTargets together with Hashes still omits sha-1 for those artifacts. Configure the output/global logger cache before target callbacks (while preserving the per-target cache as needed).
            if (context.DataToInsert.HasFlag(OptionallyEmittedData.Hashes))
            {
                context.Logger.FileRegionsCache = new FileRegionsCache(
                    fileSystem: context.FileSystem,
                    hashAlgorithms: HashAlgorithms.Sha1 | HashAlgorithms.Sha256);
  • Files reviewed: 2/2 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

<PackageVersion Include="Moq" Version="4.20.72" />
<PackageVersion Include="Newtonsoft.Json" Version="13.0.4" />
<PackageVersion Include="Sarif.Driver" Version="4.6.0" />
<PackageVersion Include="Sarif.Driver" Version="5.7.0" />
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .net code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants