What changed, and why it matters
This commit updates many third-party software libraries used by BTCPay Server to newer versions. The changes also adjust how FIDO2/WebAuthn security-key support is configured to match the newer library. Dependency bumps can fix security bugs in those libraries, but the commit message does not say which bugs are being fixed, and the diff itself does not show any direct security patch in BTCPay Server's own code.
Treat this as a routine dependency-maintenance commit. Review the release notes and security advisories for the upgraded packages (especially Fido2 4.2.0, YamlDotNet 18.1.0, TwentyTwenty.Storage 3.0.0, and Microsoft.AspNetCore/EntityFrameworkCore 10.0.12) to determine whether any CVEs were fixed. Run regression tests for FIDO2 login, YAML configuration/import features, and cloud storage integrations. No immediate emergency response is warranted based solely on the diff.
Security signals we found
Dependency version bumps may include undisclosed security fixes in upstream packages
Fido2 library major-ish upgrade (4.0.1→4.2.0) with API renames suggests upstream breaking changes, possibly including security hardening
YamlDotNet major version jump (16.3.0→18.1.0) could address parser security issues historically present in YAML libraries
TwentyTwenty.Storage major version jump (2.26.1→3.0.0) may include cloud-storage security fixes
No explicit security claim, CVE reference, or vulnerability description in commit message or diff
Evidence from the diff
The commit bumps NuGet package versions across the solution: Microsoft.AspNetCore/EntityFrameworkCore packages from 10.0.11 to 10.0.12, Dapper 2.1.79→2.1.89, Microsoft.CodeAnalysis.CSharp 5.6.0→5.9.0, test packages (Playwright, xunit, etc.), YamlDotNet 16.3.0→18.1.0, Fido2/Fido2.AspNet 4.0.1→4.2.0, MailKit 4.17.0→4.18.1, and TwentyTwenty.Storage packages 2.26.1→3.0.0. Startup.cs adapts to Fido2 4.x API renames: ServerName→RPName, ServerDomain→RPID, and the metadata-service registration is refactored. The test harness removes the FIDO metadata service to avoid external network/rate-limit dependencies during tests. No explicit CVE, advisory, or security rationale is provided in the commit or supplied references.
Changed components
BTCPayServer.Abstractions/BTCPayServer.Abstractions.csprojBTCPayServer.Data/BTCPayServer.Data.csprojBTCPayServer.Rating/BTCPayServer.Rating.csprojBTCPayServer.Tests/BTCPayServer.Tests.csprojBTCPayServer.Tests/BTCPayServerTester.csBTCPayServer/BTCPayServer.csprojBTCPayServer/Hosting/Startup.csFIDO2/WebAuthn authentication subsystemYAML parsing subsystemCloud storage subsystem (Amazon/Azure/Google/Local via TwentyTwenty.Storage)Inspect captured patch +30 / −29
### BTCPayServer.Abstractions/BTCPayServer.Abstractions.csproj
@@ -32,8 +32,8 @@
</ItemGroup>
<ItemGroup>
<PackageReference Include="HtmlSanitizer" Version="9.2.1039" />
- <PackageReference Include="Microsoft.AspNetCore.SignalR.Protocols.NewtonsoftJson" Version="10.0.11" />
- <PackageReference Include="Microsoft.EntityFrameworkCore" Version="10.0.11" />
+ <PackageReference Include="Microsoft.AspNetCore.SignalR.Protocols.NewtonsoftJson" Version="10.0.12" />
+ <PackageReference Include="Microsoft.EntityFrameworkCore" Version="10.0.12" />
<PackageReference Include="Npgsql.EntityFrameworkCore.PostgreSQL" Version="10.0.3" />
</ItemGroup>
<ItemGroup>
### BTCPayServer.Data/BTCPayServer.Data.csproj
@@ -3,14 +3,14 @@
<Import Project="../Build/Common.csproj" />
<ItemGroup>
<FrameworkReference Include="Microsoft.AspNetCore.App" />
- <PackageReference Include="Microsoft.EntityFrameworkCore" Version="10.0.11" />
- <PackageReference Include="Microsoft.EntityFrameworkCore.Design" Version="10.0.11">
+ <PackageReference Include="Microsoft.EntityFrameworkCore" Version="10.0.12" />
+ <PackageReference Include="Microsoft.EntityFrameworkCore.Design" Version="10.0.12">
<PrivateAssets>all</PrivateAssets>
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
</PackageReference>
- <PackageReference Include="Microsoft.AspNetCore.Identity.EntityFrameworkCore" Version="10.0.11" />
+ <PackageReference Include="Microsoft.AspNetCore.Identity.EntityFrameworkCore" Version="10.0.12" />
<PackageReference Include="NBitcoin.Altcoins" Version="6.0.9" />
- <PackageReference Include="Dapper" Version="2.1.79" />
+ <PackageReference Include="Dapper" Version="2.1.89" />
</ItemGroup>
<ItemGroup>
<ProjectReference Include="..\BTCPayServer.Abstractions\BTCPayServer.Abstractions.csproj" />
### BTCPayServer.Rating/BTCPayServer.Rating.csproj
@@ -4,7 +4,7 @@
<ItemGroup>
<FrameworkReference Include="Microsoft.AspNetCore.App" />
- <PackageReference Include="Microsoft.CodeAnalysis.CSharp" Version="5.6.0" />
+ <PackageReference Include="Microsoft.CodeAnalysis.CSharp" Version="5.9.0" />
<PackageReference Include="Microsoft.AspNet.WebApi.Client" Version="6.0.0" />
<PackageReference Include="NBitcoin" Version="10.0.14" />
<PackageReference Include="Newtonsoft.Json" Version="13.0.4" />
### BTCPayServer.Tests/BTCPayServer.Tests.csproj
@@ -41,11 +41,11 @@
</ItemGroup>
<ItemGroup>
- <PackageReference Include="Microsoft.Playwright" Version="1.62.0" />
- <PackageReference Include="Microsoft.Testing.Extensions.GitHubActionsReport" Version="1.0.0-alpha.26377.5" />
- <PackageReference Include="Newtonsoft.Json.Schema" Version="4.0.1" />
- <PackageReference Include="Microsoft.AspNetCore.Mvc.Razor.RuntimeCompilation" Version="10.0.11" />
- <PackageReference Include="xunit.v3" Version="4.0.0" />
+ <PackageReference Include="Microsoft.Playwright" Version="1.63.0" />
+ <PackageReference Include="Microsoft.Testing.Extensions.GitHubActionsReport" Version="2.4.1" />
+ <PackageReference Include="Newtonsoft.Json.Schema" Version="4.0.2" />
+ <PackageReference Include="Microsoft.AspNetCore.Mvc.Razor.RuntimeCompilation" Version="10.0.12" />
+ <PackageReference Include="xunit.v3" Version="4.0.1" />
</ItemGroup>
<ItemGroup>
<None Update=".dockerignore">
### BTCPayServer.Tests/BTCPayServerTester.cs
@@ -22,6 +22,7 @@
using BTCPayServer.Services.Stores;
using BTCPayServer.Tests.Logging;
using BTCPayServer.Tests.Mocks;
+using Fido2NetLib;
using Microsoft.AspNetCore.Hosting;
using Microsoft.AspNetCore.Hosting.Server.Features;
using Microsoft.AspNetCore.Http;
@@ -249,6 +250,8 @@ public async Task StartAsync()
.UseStartup<Startup>()
.ConfigureServices(services =>
{
+ // Keep test hosts independent of FIDO Metadata Service availability and rate limits.
+ services.RemoveAll<IMetadataService>();
if (RuntimeCompilation)
services.AddMvcCore().AddRazorRuntimeCompilation();
### BTCPayServer/BTCPayServer.csproj
@@ -35,15 +35,15 @@
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
</PackageReference>
<PackageReference Include="NBitcoin" Version="10.0.14" />
- <PackageReference Include="YamlDotNet" Version="16.3.0" />
+ <PackageReference Include="YamlDotNet" Version="18.1.0" />
<PackageReference Include="BIP78.Sender" Version="0.2.5" />
<PackageReference Include="BTCPayServer.Hwi" Version="2.0.6" />
<PackageReference Include="BTCPayServer.Lightning.All" Version="1.7.12" />
<PackageReference Include="CsvHelper" Version="33.1.0" />
- <PackageReference Include="Fido2" Version="4.0.1" />
- <PackageReference Include="Fido2.AspNet" Version="4.0.1" />
+ <PackageReference Include="Fido2" Version="4.2.0" />
+ <PackageReference Include="Fido2.AspNet" Version="4.2.0" />
<PackageReference Include="LNURL" Version="0.0.36" />
- <PackageReference Include="MailKit" Version="4.17.0" />
+ <PackageReference Include="MailKit" Version="4.18.1" />
<PackageReference Include="QRCoder" Version="1.8.0" />
<PackageReference Include="NBitpayClient" Version="1.0.0.39" />
<PackageReference Include="Newtonsoft.Json" Version="13.0.4" />
@@ -53,13 +53,13 @@
<PackageReference Include="Serilog" Version="4.4.0" />
<PackageReference Include="Serilog.AspNetCore" Version="10.0.0" />
<PackageReference Include="Serilog.Sinks.File" Version="7.0.0" />
- <PackageReference Include="TwentyTwenty.Storage" Version="2.26.1" />
- <PackageReference Include="TwentyTwenty.Storage.Amazon" Version="2.26.1" />
- <PackageReference Include="TwentyTwenty.Storage.Azure" Version="2.26.1" />
- <PackageReference Include="TwentyTwenty.Storage.Google" Version="2.26.1" />
- <PackageReference Include="TwentyTwenty.Storage.Local" Version="2.26.1" />
+ <PackageReference Include="TwentyTwenty.Storage" Version="3.0.0" />
+ <PackageReference Include="TwentyTwenty.Storage.Amazon" Version="3.0.0" />
+ <PackageReference Include="TwentyTwenty.Storage.Azure" Version="3.0.0" />
+ <PackageReference Include="TwentyTwenty.Storage.Google" Version="3.0.0" />
+ <PackageReference Include="TwentyTwenty.Storage.Local" Version="3.0.0" />
<PackageReference Include="Microsoft.AspNetCore.Mvc.NewtonsoftJson" Version="10.0.12" />
- <PackageReference Include="Microsoft.AspNetCore.SignalR.Protocols.NewtonsoftJson" Version="10.0.11" />
+ <PackageReference Include="Microsoft.AspNetCore.SignalR.Protocols.NewtonsoftJson" Version="10.0.12" />
</ItemGroup>
<ItemGroup>
### BTCPayServer/Hosting/Startup.cs
@@ -134,22 +134,20 @@ public void ConfigureServices(IServiceCollection services)
});
services.AddFido2(options =>
{
- options.ServerName = "BTCPay Server";
+ options.RPName = "BTCPay Server";
})
- .AddCachedMetadataService(config =>
- {
- config.AddFidoMetadataRepository();
- });
+ .AddCachedMetadataService()
+ .AddFidoMetadataRepository();
var descriptor = services.Single(descriptor => descriptor.ServiceType == typeof(Fido2Configuration));
services.Remove(descriptor);
services.AddScoped(provider =>
{
var httpContext = provider.GetService<IHttpContextAccessor>();
return new Fido2Configuration()
{
- ServerName = "BTCPay Server",
+ RPName = "BTCPay Server",
Origins = new[] { $"{httpContext.HttpContext.Request.Scheme}://{httpContext.HttpContext.Request.Host}" }.ToHashSet(),
- ServerDomain = httpContext.HttpContext.Request.Host.Host
+ RPID = httpContext.HttpContext.Request.Host.Host
};
});
services.AddScoped<Fido2Service>();Why this scored 29/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.