Why
dotnet list PayBridge.SDK.sln package --vulnerable --include-transitive reports high-severity advisories in SQLitePCLRaw.lib.e_sqlite3 2.1.6 and System.Text.Json 8.0.0 across the SDK, tests, example, and presentation projects. Repository vulnerability alerts are currently disabled.
Scope
- Upgrade the .NET 8 dependency graph to patched, compatible versions.
- Prefer current .NET 8 servicing releases rather than moving target frameworks as part of this fix.
- Enable Dependabot vulnerability alerts and dependency update configuration.
- Add a CI dependency-vulnerability check with an explicit severity policy.
Acceptance criteria
Why
dotnet list PayBridge.SDK.sln package --vulnerable --include-transitivereports high-severity advisories inSQLitePCLRaw.lib.e_sqlite3 2.1.6andSystem.Text.Json 8.0.0across the SDK, tests, example, and presentation projects. Repository vulnerability alerts are currently disabled.Scope
Acceptance criteria