Security
Security in Aspose.Slides
Aspose applies best practices when developing its products.
- Aspose.Slides for .NET is used to manipulate presentations and to convert them to other formats. It does not run scripts in presentations. Aspose.Slides parses the presentation structure and lets the end user’s code manipulate the object model in a convenient way.
- Aspose.Slides functions as a library that parses and interprets documents without executing remote code. All Aspose products run on your machines. They do not transmit any data to Aspose. The only exception is a metered license: if you use one, only your API usage information is processed.
- Aspose components run in the same user context as regular applications. Therefore, Aspose components do not pose a risk to vital system resources. Furthermore, when an Aspose component opens a document, macros are not run automatically.
- The risks inherent in or associated with the Microsoft Office package do not apply to Aspose components, so Aspose products are very secure.
NuGet Dependencies
Aspose.Slides for .NET depends on packages that Microsoft publishes on NuGet. The dependencies differ by package and target framework:
| Package | Target framework | Dependencies |
|---|---|---|
| Aspose.Slides.NET | net462 |
System.Text.Json |
| Aspose.Slides.NET | net6.0 |
System.Drawing.Common, System.Security.Cryptography.Xml |
| Aspose.Slides.NET | netstandard2.0 |
System.Drawing.Common, System.Security.Cryptography.Xml, System.Text.Encoding.CodePages, System.Text.Json |
| Aspose.Slides.NET6.CrossPlatform | net6.0 |
System.Security.Cryptography.Xml |
The Dependencies section of the Aspose.Slides.NET and Aspose.Slides.NET6.CrossPlatform pages on NuGet lists the minimum version of each dependency for every release.
When you add Aspose.Slides to a project, NuGet also restores the dependencies of these packages. To list every package that your project restores, including these transitive dependencies, run this command in the project folder:
dotnet list package --include-transitive
To check the same set of packages against known vulnerabilities, run:
dotnet list package --vulnerable --include-transitive
For other ways to audit NuGet packages, see Auditing package dependencies for security vulnerabilities.
Third-Party Components
Aspose.Slides includes code from third-party open-source components. They are part of the product, not separate NuGet packages, so tools that read only NuGet dependencies do not list them. Both packages contain the file thirdpartylicenses.Aspose.Slides.for.NET.pdf, which lists the components and their licenses:
| Component | License stated in the notice |
|---|---|
| DotNetZip | Microsoft Public License (Ms-PL) |
| ANTLR | BSD License |
| sfntly | Apache License 2.0 |
| Skia | BSD-style license |
| HarfBuzz | “Old MIT” license |
| Boost | Boost Software License 1.0 |
| Double Conversion | BSD-style license |
| ICU (International Components for Unicode) | Unicode copyright and terms of use |
FAQ
What systems are used to monitor for vulnerabilities in Aspose code?
We run a static code analysis for every Aspose.Slides release. We can provide security reports that prove Aspose.Slides code passes OWASP Top 10.
Does Aspose.Slides use external packages?
Yes. It depends on the Microsoft NuGet packages listed in NuGet Dependencies, and it includes the third-party components listed in Third-Party Components. Include both in your security review, and use dotnet list package --vulnerable --include-transitive to check the NuGet packages that your project restores.