Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
# GitHub Copilot Instructions

Read and follow [AGENTS.md](../AGENTS.md) as the repository-wide source of coding, performance, and verification requirements. Prefer existing local patterns and repository configuration whenever generated code or suggestions are accepted.
62 changes: 9 additions & 53 deletions .github/workflows/build-and-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,31 +19,7 @@ jobs:
isARM:
- ${{ contains(github.event.pull_request.labels.*.name, 'arch:arm32') || contains(github.event.pull_request.labels.*.name, 'arch:arm64') }}
options:
- os: ubuntu-latest
framework: net7.0
sdk: 7.0.x
sdk-preview: true
runtime: -x64
codecov: false
- os: macos-26-intel
framework: net7.0
sdk: 7.0.x
sdk-preview: true
runtime: -x64
codecov: false
- os: windows-latest
framework: net7.0
sdk: 7.0.x
sdk-preview: true
runtime: -x64
codecov: false
- os: buildjet-4vcpu-ubuntu-2204-arm
framework: net7.0
sdk: 7.0.x
sdk-preview: true
runtime: -x64
codecov: false
- os: ubuntu-latest
- os: ubuntu-22.04
framework: net6.0
sdk: 6.0.x
runtime: -x64
Expand All @@ -53,15 +29,20 @@ jobs:
sdk: 6.0.x
runtime: -x64
codecov: false
- os: windows-latest
- os: windows-2022
framework: net6.0
sdk: 6.0.x
runtime: -x64
codecov: true
- os: ubuntu-22.04-arm
framework: net6.0
sdk: 6.0.x
runtime: -x64
codecov: false
exclude:
- isARM: false
options:
os: buildjet-4vcpu-ubuntu-2204-arm
os: ubuntu-22.04-arm

runs-on: ${{matrix.options.os}}

Expand Down Expand Up @@ -110,49 +91,24 @@ jobs:
restore-keys: ${{ runner.os }}-nuget-

- name: DotNet Setup
if: ${{ matrix.options.sdk-preview != true }}
uses: actions/setup-dotnet@v4
with:
dotnet-version: |
6.0.x

- name: DotNet Setup Preview
if: ${{ matrix.options.sdk-preview == true }}
uses: actions/setup-dotnet@v4
with:
dotnet-version: |
7.0.x

- name: DotNet Build
if: ${{ matrix.options.sdk-preview != true }}
shell: pwsh
run: ./ci-build.ps1 "${{matrix.options.framework}}"
env:
SIXLABORS_TESTING: True

- name: DotNet Build Preview
if: ${{ matrix.options.sdk-preview == true }}
shell: pwsh
run: ./ci-build.ps1 "${{matrix.options.framework}}"
env:
SIXLABORS_TESTING_PREVIEW: True

- name: DotNet Test
if: ${{ matrix.options.sdk-preview != true }}
shell: pwsh
run: ./ci-test.ps1 "${{matrix.options.os}}" "${{matrix.options.framework}}" "${{matrix.options.runtime}}" "${{matrix.options.codecov}}"
env:
SIXLABORS_TESTING: True
XUNIT_PATH: .\tests\ImageSharp.Drawing.Tests # Required for xunit

- name: DotNet Test Preview
if: ${{ matrix.options.sdk-preview == true }}
shell: pwsh
run: ./ci-test.ps1 "${{matrix.options.os}}" "${{matrix.options.framework}}" "${{matrix.options.runtime}}" "${{matrix.options.codecov}}"
env:
SIXLABORS_TESTING_PREVIEW: True
XUNIT_PATH: .\tests\ImageSharp.Drawing.Tests # Required for xunit

- name: Export Failed Output
uses: actions/upload-artifact@v4
if: failure()
Expand All @@ -170,7 +126,7 @@ jobs:
Publish:
needs: [Build]

runs-on: ubuntu-latest
runs-on: ubuntu-22.04

if: (github.event_name == 'push')

Expand Down
43 changes: 43 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
# Six Labors AI Coding Guidelines

These instructions apply to the entire repository. More-specific `AGENTS.md` files may add to or override them for their directory tree.

## Working Practices

- Inspect only the source and supporting files needed for the task before proposing or making changes. Do not infer current behavior when the source is available.
- Make the smallest complete change that solves the requested problem. Avoid unrelated cleanup, speculative abstractions, and formatting churn.
- Trace the existing execution path before changing it. Extend and optimize the existing implementation within the requested behavior and affected path.
- Before implementing an operation, find and inspect the existing APIs that provide it. Use or extend those APIs instead of writing equivalent logic elsewhere. This includes color conversion, pixel conversion, memory management, and vectorized operations. If an API lacks required behavior, improve its owning implementation rather than bypassing it with a separate implementation.
- Follow existing naming, formatting, documentation, and test patterns. Treat `.editorconfig`, analyzers, and repository build settings as authoritative.
- Use simple technical English in all communication, documentation, and comments. Use short sentences, active voice, and existing code terminology.
- Preserve public API and observable behavior unless the task explicitly requires a change. Public API documentation must describe observable behavior, not implementation details.
- Do not use reflection against built assemblies, ad hoc assembly loading, or temporary probe projects unless explicitly requested.
- Build .NET projects in Release configuration unless explicitly instructed otherwise.

## Performance

- Treat throughput, latency, memory use, and binary size as design constraints, especially in pixel-processing, drawing, parsing, encoding, and other hot paths.
- Avoid unnecessary allocations, copies, boxing, closures, interface dispatch, repeated enumeration, and extra passes over data.
- Reuse existing memory ownership, pooling, span, vectorization, and parallelization mechanisms.
- Use a SIMD-first design for suitable data processing code. Build on existing vectorized operations, dispatch mechanisms, and scalar fallbacks. Keep hot loops simple, hoist invariant work, and preserve memory locality.
- Preserve correctness and maintainability during optimization. Distinguish source-based reasoning from measured results. Claim a speedup only with measurements. Use existing benchmarks first. Add or update cases only when they measure relevant behavior that existing benchmarks miss.
- Consider all supported target frameworks and runtime capabilities. Do not regress fallback paths while optimizing newer runtimes.

## C# Conventions

- Follow local patterns when they comply with the explicit rules.
- Do not use `record` or `record struct` types.
- Prefer established invariants over redundant guards. Validate at real external boundaries and do not add defensive checks for internally controlled states.
- Do not extract single-use helpers merely to name a block. Extract only for genuine reuse, an established local pattern, or independently complex logic.
- Add vertical whitespace after multi-line statements and declarations and between distinct logical stages. Never add trailing whitespace.
- Document every added method, constructor, and property, regardless of visibility. Update documentation when a member's behavior or contract changes. Keep public API documentation limited to observable behavior. Use private and internal documentation to explain the contract and intent.
- Add inline comments that explain why complex code works. Explain algorithms, formulas, invariants, memory ownership, compatibility behavior, and performance decisions where they apply.
- For SIMD, explain lane layouts, operations, alignment, remainders, and scalar equivalence so an unfamiliar maintainer can follow the code.

## Verification

- Add or update tests only when they prove a required behavior or expose a real defect. Derive expectations from established contracts, explicit requirements, or defect evidence. Use source to identify contracts and integration points, not to copy implementation results into expectations. Prefer extending existing tests. Avoid redundant cases and assertions that merely repeat the implementation.
- Never weaken, skip, or bypass a valid test to make it pass. Fix the production defect or the genuine test defect. Replace or remove a test only with evidence that its expectation is invalid or its coverage is redundant.
- Do not update golden files, reference images, snapshots, baselines, or expected-output artifacts merely to silence a failure. Investigate mismatches. Update expected results only for an established requirement change or an incorrect reference result proved by independent contract or defect evidence.
- Test the actual behavior through the existing execution path. Synthetic inputs must exercise an established requirement or reproduce a real defect. Do not invent requirements or substitute internal structure and helper calls for assertions about required behavior. Run the narrowest relevant formatting, test, and Release build commands.
- Report what changed, the verification performed, and any remaining risks or unverified assumptions.
3 changes: 3 additions & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
# Claude Code Instructions

Read and follow [AGENTS.md](AGENTS.md) as the repository-wide source of coding, performance, and verification requirements. Apply any more-specific `AGENTS.md` or `CLAUDE.md` found below the files being changed.
3 changes: 3 additions & 0 deletions GEMINI.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
# Gemini CLI Instructions

Read and follow [AGENTS.md](AGENTS.md) as the repository-wide source of coding, performance, and verification requirements. Apply any more-specific `AGENTS.md` or `GEMINI.md` found below the files being changed.
103 changes: 103 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,103 @@
# Security Policy

## Supported Versions

Six Labors provides security updates for the latest major version of each library.

Each major version remains eligible for security updates for 12 months after the first stable release of the next major version of that library.
After this period, that major version is end-of-life and does not receive security updates.

Users must install the latest available patch or minor release within a supported major version to receive security fixes.
Older releases within that major version are not maintained separately.

| Version | Supported |
| ------- | --------- |
| Latest major version | Yes |
| Superseded major version within 12 months of the next major's first stable release | Yes |
| Superseded major version after that 12-month period | No |

Security updates may require a license key under the existing license terms. This does not change the license terms.

This policy covers security fixes only. It does not include feature backports or extend support for underlying .NET versions.

Security fixes, if any, are provided at Six Labors' discretion.

This policy does not create any obligation to provide support, maintenance services, SLAs, custom fixes, hosted services, managed services, operational monitoring, professional services, consulting, or certification of customer products.

## Reporting a Vulnerability

Please report suspected security vulnerabilities using GitHub private vulnerability reporting for the relevant Six Labors repository, where available.

If GitHub private vulnerability reporting is not available for a repository, please report suspected security vulnerabilities by contacting Six Labors through the contact details published on the Six Labors website.

Do not report security vulnerabilities through public GitHub issues.

When reporting a vulnerability, please include as much relevant information as possible:

* affected package and version
* target framework and runtime
* operating system
* input file or minimal reproduction, if safe to share
* expected and actual behavior
* potential security impact
* whether you believe the issue is being actively exploited

Six Labors may review reported vulnerabilities and determine whether they are security issues affecting a supported version.

A report may be declined or closed without action if, in Six Labors' opinion, it:

* is not reproducible
* does not affect a supported version
* affects only an unsupported or end-of-life version
* is not a security vulnerability
* depends on unsafe, unsupported, or unintended use
* depends on a vulnerable application, environment, dependency, configuration, or deployment outside the Six Labors library itself
* lacks sufficient information for assessment
* is duplicative
* has already been fixed
* is otherwise outside the scope of this policy

If a vulnerability is accepted, Six Labors may handle it through GitHub Security Advisories and, where appropriate, CVE assignment.

Six Labors does not guarantee any response time, fix time, release date, advisory publication date, CVE assignment, workaround, mitigation, or particular outcome for any report.

## Scope

This policy applies only to security vulnerabilities in Six Labors libraries themselves.

This policy does not apply to:

* customer applications
* customer products
* customer deployments
* customer infrastructure
* customer data
* third-party services
* unsupported versions
* end-of-life versions
* forks or modified versions
* usage outside the documented or intended behavior of the relevant library

Organizations using Six Labors libraries are responsible for assessing, securing, testing, monitoring, updating, and maintaining their own applications, products, deployments, infrastructure, and supply chains.

## Cyber Resilience Act

Six Labors libraries are general-purpose software libraries.

They are not cybersecurity products, identity or access management systems, password managers, operating systems, browsers, firewalls, network management tools, SIEM tools, hypervisors, container runtimes, or other Cyber Resilience Act important or critical product classes.

If a Six Labors library is treated as a product with digital elements under the Cyber Resilience Act, Six Labors assesses it as an ordinary software component.

Organizations incorporating Six Labors libraries into products made available on the EU market are responsible for assessing and meeting their own regulatory obligations for those products, including any obligations under the Cyber Resilience Act.

Six Labors does not provide support, maintenance services, SLAs, managed services, hosted services, operational monitoring, custom fixes, professional services, consulting, or certification of customer products.

Security vulnerabilities in supported Six Labors libraries are handled through the GitHub Security Advisory process for the relevant repository, where appropriate.

From 11 September 2026, if Six Labors becomes aware of credible active exploitation of a vulnerability in a supported Six Labors library, or a severe security incident affecting a supported Six Labors library, Six Labors may report the matter through the applicable Cyber Resilience Act reporting mechanism where legally required.

## No Warranty

Six Labors libraries are provided in accordance with their applicable license terms.

Nothing in this policy creates any warranty, representation, guarantee, support obligation, maintenance obligation, service commitment, regulatory certification, or assumption of responsibility for any customer product, customer deployment, customer compliance obligation, or third-party system.
16 changes: 12 additions & 4 deletions src/ImageSharp.Drawing/ImageSharp.Drawing.csproj
Original file line number Diff line number Diff line change
Expand Up @@ -15,8 +15,8 @@
</PropertyGroup>

<PropertyGroup>
<!--Bump to V2 prior to tagged release.-->
<MinVerMinimumMajorMinor>2.0</MinVerMinimumMajorMinor>
<!--Set the minimum version for the release branch.-->
<MinVerMinimumMajorMinor>2.2</MinVerMinimumMajorMinor>
</PropertyGroup>

<!-- This enables the nullable analysis and treats all nullable warnings as error-->
Expand Down Expand Up @@ -45,8 +45,16 @@
<None Include="..\..\shared-infrastructure\branding\icons\imagesharp.drawing\sixlabors.imagesharp.drawing.128.png" Pack="true" PackagePath="" />
</ItemGroup>
<ItemGroup>
<PackageReference Include="SixLabors.Fonts" Version="2.1.3" />
<PackageReference Include="SixLabors.ImageSharp" Version="3.1.11" />
<PackageReference Include="SixLabors.Fonts" Version="2.2.0" />
<PackageReference Include="SixLabors.ImageSharp" Version="3.2.0" />
</ItemGroup>
<ItemGroup>
<!-- These issues are fixed in ImageSharp 3.2.0. Remove the suppressions when the advisory database corrections are published. -->
<NuGetAuditSuppress Include="https://github.com/advisories/GHSA-gwg2-r3hj-4w44" />
<NuGetAuditSuppress Include="https://github.com/advisories/GHSA-j3p4-wp97-rph4" />
<NuGetAuditSuppress Include="https://github.com/advisories/GHSA-j9gm-c75j-xc9q" />
<NuGetAuditSuppress Include="https://github.com/advisories/GHSA-jjfr-hcj7-qf5w" />
<NuGetAuditSuppress Include="https://github.com/advisories/GHSA-wmxv-xphr-5c9g" />
</ItemGroup>
<Import Project="..\..\shared-infrastructure\src\SharedInfrastructure\SharedInfrastructure.projitems" Label="Shared" />
</Project>
2 changes: 1 addition & 1 deletion src/ImageSharp.Drawing/Shapes/PathBuilder.cs
Original file line number Diff line number Diff line change
Expand Up @@ -445,7 +445,7 @@ public PathBuilder Reset()
/// <summary>
/// Clears all drawn paths, Leaving any applied transforms.
/// </summary>
[MemberNotNull(nameof(this.currentFigure))]
[MemberNotNull(nameof(currentFigure))]
public void Clear()
{
this.currentFigure = new Figure();
Expand Down
Loading