
Sign up to save your podcasts
Or


Last Week in .NET - Week Ending 25 July 2020
More on CVE-2020-1147
Do you deserialize XML to a DataSet? This is about CVE-2020-1147.
More details on CVE-2020-1147 -- that Remote Code Execution Vulnerability for .NET Core. Turns out it has to do with deserializing XML into a DataSet. If this is something you do; stop reading and go patch your application to .NET Core to 3.1.6, .NET Core 2.1.20; and .NET 5 Preview 7. Make sure to update the SDK running on your developer machines as well. There's a bit more information than I was able to get last week.
Special Thanks (again) to @vcsjones on twitter.
Microsoft talks about Windows 10X
Apparently in Windows 10X, Win32 applications will be virtualized and served "over the cloud". OK. This is both interesting, frightens the hell out of me, and makes me wonder at what point we lose control of our Operating Systems completely.
.NET 5 Preview 7 has been released
This includes changes to the runtime, SDK, ASP.NET Core, and Entity Framework Core.
For the Runtime, there's a lingering bug with Regex that you can fix by removing RegexCompiled, you know, what keeps regex's fast. Anyway, if you're running .NET 5 Preview 7 in production, that's something to be aware of.
For ASP.NET Core, there are cookie and blazor bugs fixed, and there's also a blog post out about Preview 7 that talks about the blazor improvements especially. Blazor is getting a lot of attention from Microsoft, and this is great, especially since there are thousands of applications that are in Web Forms that have no upgrade path at all to .NET 5. How does Blazor help here, you ask? Well, it at least gives political cover to the idea that it's possible, but if you read the documentation around converting an ASP.NET Webforms application to blazor, you'll notice it's currently... incomplete. Incomplete here means that there is currently no migration path for built in Webforms controls.
Without Microsoft providing some sort of conversion system for WebForms, organizations will be forced to rewrite their WebForms applications anyway; and Microsoft is hoping they'll choose Blazor.
I may have blown the spoiler; but Blazor is now a part of .NET 5. There's more work to do, but this is a great start.
There's a lot of fixes in Entity Framework Core 5.0.0 Preview 7., too numerous to list here. If you use EF Core, you may want to pay attention.
.NET Framework (Not Core, or 5) July 2020 Cumulative Update Preview is released
This preview fixes several bugs uncovered in .NET Framework 4.8 including a memory leak in HttpListener, and a bug in SqlBulkCopy that would cause writes to fail, there are fixes in WCF, WPF, and Windows Forms, and Accessibility Improvements in Windows Forms.
A 'replacement' for SecureString is being bandied about for .NET 6:
SecureString, the oft-maligned and probably most misused class in .NET, is getting its hair re-done as "ShroudedBuffer" as a part of .NET 6. The name change and API change is to help reiterate that this string isn't a "SecurityFeature", rather it's a signal that if you're trying to log stuff; YOU SHOULDN'T LOG THIS.
I'm not sold on the name; but naming is hard. My personal list contains candidates such as OpaqueString, or "Dont^%&DFingLogThisString" or "SensitiveBuffer", or ClassifiedBuffer, or ConfidentialString".
EFCore now supports Many-To-Many relationships
I didn't know it didn't; and I feel bad for everyone that now has to either 1) maintain the workarounds they used to get that support before, or 2) retrofit this approach into their code. You can read more about Many-to-Many support here. No word on when this lands in a release, but it'll either be in .NET 5 Preview 8 or .NET 5 RC 1.
Bug in .NET Core 3.1 causes SkipLast and TakeLast to return the wrong value:
What happens when you add highly performant code that has bugs? You get fast bugs. If you use SkipLast and TakeLast in .NET Core 3.1, there's a good chance you'll encounter this bug if your source collection you're operating on is a List; which of course is just about everyone.
.NET Foundation Elections Board happening Now
The .NET Foundation Board elections are happening right now. If you're a member of the .NET Foundation, GO VOTE. If you're not a member, you should be. Go join up, then go vote.
If you want to hear from the candidates themselves, the .NET Foundation held interviews with board candidates; they're worth your time.
Stack Overflow elections are over, two new moderators elected
Stack Overflow just wrapped up their moderator elections, and despite a dismal number of moderator candidates, there were two new moderators elected. Please welcome Makyen and Machavity
PFCLotW (Pretty Fricking Cool Library of the Week)
Do you write distributed applications? First off, I'm sorry. Second, have you thought about using Akka.NET? Distributed applications are hard, and without a framework to help you along, you're going to be spending a lot of time working around the fact that your application is, in fact, distributed. This is not a sponsored ad, and I hope to never make another distributed application; but if I did, I'd give Akka.NET a serious look.
And that's what happened Last Week in .NET.
I'm George Stocker, and I teach TDD to .NET teams. This isn't your grandfather's TDD, no. It's actually meant to be used in large applications without use of Mocks or stubs, and without the inherent pain ...
We see you, Jilthub
Github, the eponymous source control collaboration system for Open Source Projects, owned by Microsoft, has been caught trying to sneakily continue its contracts with ICE -- you know, the government agency that puts kids in cages -- by getting a contract award from ICE through Dell Federal Systems.
Now all of this may be on the up-and-up; Dell sells Github enterprise to ICE as a reseller, Github gets plausible deniability, and ICE gets to use the cool kids source control system.
But it's still morally bankrupt for Github to take this contract -- for an amount, I might add, that totals $79,312.50, or roughly the same amount Microsoft should have paid Keivan for using his AppGet architectural work in their WinGet package manager solution.
We see you, Github. Special thanks to [Dave Copeland](https://twitter.com/davetron5000/status/1282738504624222208?s=20) for making me aware of this. Twitter is sometimes a beautiful thing.
Github 'offers' to let Non-US employees do the same job for half the pay.
Microsoft's github acquired NPM. They [apprently "offered" to reduce non US employees compensation by up to 50%.](https://twitter.com/nomadtechie/status/1283613109932961792?s=20) to do the same job.
In the Year of our Lord 2020 it is very impressive that a company like Github, who are still reeling from their morally bankrupt decision to keep an ICE contract worth $79,000, would also stoop so low as to to get existing employees of NPM to quit by offering them half the money to do the same job.
When we call supporting ICE morally bankrupt, that is not meant to inspire you to be the villian, github. That's an insult, meant to shame you into doing the right thing.
Vulnerabilities reported this week
Microsoft reported and [released a fix](https://github.com/dotnet/announcements/issues/159) for CVE-2020-1147, a .NET Core Remote Code Execution Vulnerability. If you accept XML input, this advisory affects you. If any of your API endpoints accept XML, this advisory affects you. .NET Core 2.1.19, .NET 3.1.5, and .NET 5 Preview 6 are all vulnerable. This is fixed in the latest version of .NET Core 3.1.6, and will hopefully be fixed when .NET 5 Preview 7 is released.
If you are running Visual Studio 16.4, you need to update SDK to 3.1.106; if you're running Visual studio 2019 16.5 or later, update to SDK 3.1.302 and then curse version numbers loudly like I'm about to.
If you use Windows DNS Server, there's another [RCE vulnerability that is apparently "wormable"](https://msrc-blog.microsoft.com/2020/07/14/july-2020-security-update-cve-2020-1350-vulnerability-in-windows-domain-name-system-dns-server/), but [at least some infosec people seem to think it won't turn into a big problem](https://twitter.com/hackerfantastic/status/1283096226616016896?s=20). This being 2020, I'm not holding my breath.
.NET Core 2.1.20 has been released
Release Notes: https://github.com/dotnet/core/blob/master/release-notes/2.1/2.1.20/2.1.20.md
Self Contained Applications
One of the more interesting parts of .NET Core has become the "Self Contained Application" -> effectively the runtime, the application and its dependencies in one package. This is great for datacenter style deployments or cross platform console applications, or even potentially in .NET 6 with MAUI: Desktop applications. That same advantage of self-contained applications is also a disadvantage, as foretold in this note in the Announcement:
> Additionally, if you've deployed self-contained applications targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed.
Long story short: Not only do you need an update story for your organization's release cadence, that cadence must also take into account vulnerabilities in the runtime.
### Nick Craver talks Attacks on Stack Overflow.
Stack Overflow, the largest (that gets developer press and isn't Microsoft owned) site built on ASP.NET MVC (and soon .NET Core), gets a lot of attacks against it as a "top 50" (according to Wikipedia) site on the internet. Nick Craver, their architectural lead; goes deep into the sorts of attacks that happen. https://www.youtube.com/watch?v=K6NECAZhJG4 This is a good watch. Watch it.
## Improvements in .NET 5
This is the sort of thing I get jazzed about. The faster C# gets, the less we have to worry about using a language like Go or Rust for high performance situations. I don't use Rust, but anyone that does will tell you within seconds of meeting you. They're our Crossfitters.
Anyway, having an easy-to-use toolchain to write fast code is good for all of us; and really good for our economic prospects, if we're being honest. The .NET team gets jazzed about performance too, and they've released another blog post [detailing speed improvements in the forthcoming (now in Preview) .NET 5](https://devblogs.microsoft.com/dotnet/performance-improvements-in-net-5/). .NET 5, remember, is just .NET Core in a trench coat. Microsoft is going directly from .NET Core 3 to .NET 5; because awkwardly, they already have a .NET 4. I have lots of jokes to make about Microsoft Marketing, but I'd like to be clear about this: Microsoft has 20 years of inertia around the .NET Framework, and there were problem dozens of internal corporate teams that were hoping that .NET Core would fail because their bread and butter was built on .NET. Luckily it didn't fail, and luckily the group that said "Let's unify the two" won. Over time .NET Core has had to make concessions to stay in the game, like CSProj over project.json; but those concessions have ultimately scored large wins for both .NET Framework and .NET Core. This is a narrow line to walk, and for all the grief I give them, Microsoft's Marketing team is handling this with grace and aplomb.
BinaryFormatter will finally be tossed off a bridge
https://github.com/dotnet/designs/pull/141
Hashing data is now two lines of code
Special thanks to Kevin Jones [@vcsjones](https://twitter.com/vcsjones) for [making me aware of this](https://twitter.com/vcsjones/status/1283404602277335041?s=20). In likely .NET 5 Preview 8, you'll have the ability to hash data in two lines of code!:
```
ReadOnlySpan someData;
byte[] hash = SHA256.HashData(somedata);
//or
Span hashBuffer = stackalloc byte[32];
int bytesWritten = SHA256.HashData(someData, hashBuffer);
```
This is pretty and awesome. It's pretty awesome. If you find yourself producing hashes of data; it can't get much faster or easier than this.
Windows Community Toolkit 8.0.0 Preview2 for WinUI 3 Preview 2 has been released
Microsoft continues to streamline how it versions its products by overusing the word Preview. Anyway, this release lets developers kick the tires on the new WinUI, which is better known as "How you write Desktop Applications in .NET 5". The only hope I have is since they've coalesced on ridiculous versioning schemes, they've also coalesced around one way to develop Desktop Applications in .NET 5. Developers who love XAML should love WinUI 3. https://github.com/windows-toolkit/WindowsCommunityToolkit/issues/3295
ImageSharp passed 6 million downloads; and an exposure angel got their wings.
The [creator of ImageSharp laments](https://twitter.com/James_M_South/status/1282396639714373632) getting six million downloads on an open source project that obstensibly does not pay the bills. At this point in OSS, you either go APGL or...
Show notes:
Transcript:
Last Week In .NET (for the week ending July 11th, 2020)
Microsoft released details about Maui -- their codename for .NET 6.- .NET 6 is when Mono and .NET 5 aka .NET "Core" come together into a unified toolchain and platform, and they're calling it Maui. That's a bit on the nose, don't you think? Maui is the character from Moana that started, failed, stopped, started, failed, stopped, and started again and finally succeeded.
Something that I'll end up writing a thousand times because naming is hard: .NET Core is now .NET 5; and .NET Framework and .NET 5 are different incompatible things. Somebody took the Java/JavaScript comparison a bit too far. In case you haven't heard that one, Java is to JavaScript like car is to carpet.
.NET finally succeeding in bringing together Mono and .NET will be a win for everyone. If you want cross-platform Mobile Applications using .NET, you're currently stuck with Xamarin Forms and Mono. And since .NET game developers rely on Unity, and unity relies on Mono, I'll be happy to see them finally be able to move to .NET 5; since .NET Core (now .NET 5) is a lot faster than the old Framework and Mono.
The big news here is Xamarin Forms will now be a first class citizen in .NET; and cross platform Forms will now be possible. This is huge, if I'm reading it right. XAML is back too. Shout out to everyone who learned XAML only to be crushed by the demise of Silverlight. Let's all pour one out for Silverlight.
Bill Wagner, a senior content developer for .NET at Microsoft -- wait, did they get rid of Developer Advocates? Isn't a Senior Content Developer just a Developer advocate? Is nothing safe from Microsoft's Marketing team? Anyway, Bill sat down and spoke on the podcast about... .NET 6 - Codename "Maui".
Speaking of .NET 5, .NET Core 5 Preview 6 has been released. I'm also incrementing the "please move to calendar versioning" counter. This release fixes a number of issues, especially in EFCore and the .NET 5 SDK.
F# updates
For the five people that use F#, Apparently F# 5 Preview 6 is out. I'd like to thank the marketing team at Microsoft for having at least one language on the same version number as the platform now. The two holdouts are, C# which is at Version 9, and VB.NET, which is sitting at Version 16 . (which also apparently supports .NET Core? I'll have to dive in and see what this is like).
This makes me happy because F# has always felt... well.. ignored by Microsoft. Seeing them get updates for NET 5 is great. Thank you Microsoft!
EFCore Updates
Entity Framework Core version 5.0 Preview 6 is out; and once again it feels like a few microsoft teams are all "Let's pin to the platform version", and others are like "screw that". #teamplatformversion .
Anyway, from the blog post: This release includes split queries for related collections, a new “index” attribute, improved exceptions related to query translations, IP address mapping, exposing transaction id for correlation, and more.
the interesting part to me is the 'index' attribute. This support has been in Entity Framework 6.2, and is now also in EFCore as of version 5.0. In Typical MSDN fashion the API's usage is an exercise for the reader.
In the "This is scary but could be useful" department, EF Core 5 Preview 6 also released "Split Queries" support which previously existed in Entity Framework 6. Split Queries will emit separate DataReaders to retrieve data using the .Include method. On the one hand it makes query optimization easier; on the other hand it introduces a lot of magic: When you see "SplitQueryable", you now need to understand that you're hitting the database with separate queries. If you use Split Queries, let me know how you feel about them, but the DBA in me is nervous about consistency.
.NET Foundation Board Member Elections
The .NET Foundation nominations have concluded; and elections for Board Members are going to be held on July 21st. There are 6 board seats open.
AND THE NOMINEES ARE (I've always wanted to say that):
You can read about the nominees here: https://dotnetfoundation.org/about/election/candidates and best of luck to everyone who doesn't know what they're getting into.
Stack Overflow Moderator Elections
Speaking of elections, Stack Overflow is holding elections for the first time after 37 moderators left the Stack Exchange Network with 4 Moderators leaving Stack Overflow during the great Moderator exodus of 2019. That is a sordid story best told on its own. Over wine. Lots of wine. If you want me to go deeper into that story in a future podcast, post a five star review on apple podcasts, or if you're reading this newsletter in its email form, reply with the question "how many times can a company shoot itself in the foot"?
Anyway,
Nominations close on 00:00 UTC on Monday, July 13th which translates to 8pm Eastern Daylight Time on July 12th. (I think. Date math is hard. Also I apologize to my past projects and teams for advocating for the display of UTC time to every user in the application. Save your user's sanity by storing dates in UTC, and displaying them in local time).
WinGet / AppGet Debacle continues
Do you remember the time when Microsoft loved Keivan's work on AppGet, invited him out to Microsoft for an interview, ghosted him, copied several architectural features of his project and then the night before Build called him to tell him that they were releasing a competitor to his .NET open source project they were calling "WinGet"?
No? Oh.
Anyway, Keivan sat down to talk on FossBytes a...
From the publisher's feed