Skip to content

fix(web): remove vulnerable SixLabors.ImageSharp packages - #1159

Merged
sven-n merged 1 commit into
MUnique:masterfrom
eduardosmaniotto:fix/remove-imagesharp
Oct 9, 2026
Merged

sven-n merged 1 commit into
MUnique:masterfrom
eduardosmaniotto:fix/remove-imagesharp

Conversation

@eduardosmaniotto

@eduardosmaniotto eduardosmaniotto commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Removes the SixLabors.ImageSharp / SixLabors.ImageSharp.Drawing 2.1.11
dependencies, which carry known vulnerabilities (NU1902/NU1903 on every
build). Terrain rendering now uses a small dependency-free PNG encoder
(SimplePngEncoder, 8-bit RGB) plus ToPng() / ToPngDataUrl() extensions.
Rendered output is pixel-identical (black / gray safezone / green walkable).

Changes

  • Deleted the duplicated Map-local GameMapTerrainExtensions; single
    implementation in Web.Shared with named SideLength / color constants
  • MapEditor and ExitGatePicker hold a data-URL string instead of
    Image<Rgba32> (dispose bookkeeping removed; fixes an undisposed image
    in ExitGatePicker)
  • GameMapInfoExtensions render cache (ConcurrentDictionary per map
    number) unchanged, only the render body swapped
  • Package references removed from Web.Shared, Web.Map, AdminPanel
    and Directory.Packages.props

Verification

  • dotnet build Shared / Map / AdminPanel: 0 NU190x, 0 errors
  • Generated PNG validated structurally (signature, IHDR 256×256 RGB,
    chunk CRCs, IDAT size) with correct walk-green pixels
  • dotnet test MUnique.OpenMU.Web.Tests: 200/200 pass
  • Manual smoke: open map editor and exit-gate picker, confirm terrain
    renders; check live map tiles

@sven-n
sven-n merged commit b9f47e6 into MUnique:master Oct 9, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants