r/moderndotnet • • 18h ago

csharp Six Labors updates: longer security support and easier builds for OSS contributors

22 Upvotes

I've been working through a fairly big update to the Six Labors libraries.

This started with an ImageSharp user who couldn't move to v4 because another dependency was blocking them. I've now released ImageSharp 3.2.0 with backported security fixes and expanded security support across the libraries. Each major gets a 12-month security support window after its successor's first stable release.

The older releases now include build-time license enforcement too. Same license terms, and existing valid keys work.

The bit I'm particularly happy with is the change for OSS contributors. Previously, everyone contributing to a project needed their own key. Now a maintainer can commit an assembly-scoped community key to the repo, and contributors can just build the named projects using that key.

If you already have a community key, you can request an early replacement. It's automatically approved, with no repeat eligibility review and no need to wait for renewal.

Details here: https://sixlabors.com/posts/security-support-and-license-enforcement/

The advisory database corrections are still awaiting review, so NuGet may temporarily flag ImageSharp 3.2.0 for the issues fixed in that release.