NuGet auto remediation support

Why are we doing this work

.NET is widely used across enterprise environments. Extending auto-remediation to support NuGet lets .NET projects benefit from automatic MR creation for vulnerable dependency upgrades, the same way Ruby/Bundler and Java/Maven projects do today.

This is part of &19244 (Auto-remediation with automatic bumping of dependencies - GA).

Implementation plan

Package manager: nuget (*.csproj, packages.config, *.sln, Directory.Build.props, packages.lock.json). Version bumping is handled by the dependabot-nuget gem.

Updater

  • Add nuget/Dockerfile - mirrors bundler/Dockerfile/maven/Dockerfile with ARG ECOSYSTEM=nuget. Base image needs the .NET SDK since dependabot-nuget invokes dotnet/MSBuild tooling at runtime
  • Add a nuget build target to docker-bake.hcl
  • Add a release job in .gitlab/ci/jobs/release-ecosystems.yml
  • No Ruby code changes needed - PackageManager enum and EcosystemLoader already support nuget

Orchestrator

No changes required. schema.json already lists nuget as a valid package-manager value. Routing to the correct updater image is automatic.

GitLab (Rails)

  • scheduler_service.rb - add 'nuget' to SUPPORTED_PACKAGE_MANAGERS
  • job_builder.rb - add a 'nuget' => 'nuget' entry to PACKAGE_MANAGER_MAPPING
  • doc/user/application_security/remediate/auto_remediation.md - add a .NET/NuGet row to the supported package managers table

Non-functional requirements

  • Documentation: update auto_remediation.md to add NuGet (*.csproj, packages.config, packages.lock.json) to the supported package managers table
  • Feature flag: gated behind existing dependency_management_auto_remediation flag - no new flag needed
  • Performance: no impact - NuGet follows the same workload pattern as Bundler/Maven
  • Testing:
    • Updater: extend ecosystem_loader_spec.rb load table; add spec/fixtures/nuget/ fixture project; add NuGet contexts to file_fetcher_command_spec.rb, file_parser_command_spec.rb, file_updater_command_spec.rb
    • E2e: run the nuget-updater container against a real GitLab project with a known vulnerable dependency and verify output.json and MR creation end-to-end

Verification steps

  1. Enable dependency_management_auto_remediation feature flag on a test project using NuGet
  2. Ensure dependency scanning is enabled and producing results with at least one vulnerability that has a known fix version
  3. Run a pipeline and confirm an auto-remediation MR is created that bumps the vulnerable dependency in the .csproj/packages.config
  4. Confirm the MR title, description, and branch name follow the same format as Bundler/Maven MRs
  5. Merge the MR and confirm the vulnerability is resolved in the next pipeline scan
Edited by 🤖 GitLab Bot 🤖