You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让.NET 8项目中的dotnet-svcutil(v2.1.0)使用更新依赖?

问题:dotnet-svcutil v2.1.0 在.NET 8项目中触发依赖项安全警告

我在.NET 8项目中运行最新版dotnet-svcutil(v2.1.0)时,收到多个依赖项过时的安全警告,例如:

warning NU1903: Package 'System.Security.Cryptography.Pkcs' 6.0.1 has a known high severity vulnerability, https://github.com/advisories/GHSA-555c-2p6r-68mm

我已经尝试过以下指定.NET 8依赖项的方式,但问题依旧:

  • 使用dotnet SDK 8.0.202
  • 在解决方案的Directory.Build.props文件中设置<TargetFramework>net8.0</TargetFramework>
  • 执行命令时添加--targetFramework "net8.0"参数

如何确保该工具使用更新后的依赖项?


解决方法

1. 切换为本地工具替代全局工具

全局安装的dotnet-svcutil会使用自身打包时绑定的依赖版本,和项目的.NET版本不一定对齐。改用本地工具可以让工具继承项目的依赖环境:

  • 在项目根目录创建工具清单:
    dotnet new tool-manifest
    
  • 安装本地版dotnet-svcutil:
    dotnet tool install dotnet-svcutil
    
  • 之后通过本地工具执行命令:
    dotnet tool run dotnet-svcutil [你的命令参数]
    

2. 强制覆盖依赖版本

在项目的Directory.Build.props中添加依赖版本强制更新规则,让所有引用的目标包使用.NET 8兼容的最新安全版本:

<Project>
  <PropertyGroup>
    <TargetFramework>net8.0</TargetFramework>
  </PropertyGroup>
  <ItemGroup>
    <!-- 替换为对应包的最新安全版本 -->
    <PackageReference Update="System.Security.Cryptography.Pkcs" Version="8.0.0" />
    <!-- 如果有其他过时包,重复上述格式添加 -->
  </ItemGroup>
</Project>

也可以在解决方案根目录的NuGet.Config中添加绑定重定向,强制所有项目使用指定版本:

<?xml version="1.0" encoding="utf-8"?>
<configuration>
  <bindingRedirects>
    <add key="System.Security.Cryptography.Pkcs" oldVersion="0.0.0.0-8.0.0.0" newVersion="8.0.0.0" />
  </bindingRedirects>
</configuration>

3. 升级工具到预发布版本

dotnet-svcutil v2.1.0可能对.NET 8的适配存在滞后,尝试安装预发布版本获取最新的依赖修复:

# 先卸载旧版本
dotnet tool uninstall -g dotnet-svcutil
# 安装预发布版
dotnet tool install -g dotnet-svcutil --prerelease

4. 手动调整生成的引用代码

如果以上方法都无效,可先通过dotnet-svcutil生成服务引用代码,然后手动在项目中修改对应的PackageReference,将过时的依赖包替换为.NET 8兼容的版本。


内容的提问来源于stack exchange,提问作者Jacob Stamm

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 19:52:38