Skip to content

Update NuGet and System.Security.Cryptography.Xml for CG alerts#16732

Merged
missymessa merged 2 commits intomainfrom
dev/mjanecke/fix-cg-alerts-april-2026
Apr 20, 2026
Merged

Update NuGet and System.Security.Cryptography.Xml for CG alerts#16732
missymessa merged 2 commits intomainfrom
dev/mjanecke/fix-cg-alerts-april-2026

Conversation

@missymessa
Copy link
Copy Markdown
Member

@missymessa missymessa commented Apr 20, 2026

Summary

Bump vulnerable package versions to resolve Component Governance alerts from the April 2026 security patch wave.

Changes

Package Old Version New Version Advisory
NuGet.Commands 7.0.1 7.0.3 GHSA-g4vj-cjjj-v7hg
NuGet.Frameworks 7.0.1 7.0.3 GHSA-g4vj-cjjj-v7hg
NuGet.Packaging 7.0.1 7.0.3 GHSA-g4vj-cjjj-v7hg
NuGet.ProjectModel 7.0.1 7.0.3 GHSA-g4vj-cjjj-v7hg
NuGet.Versioning 7.0.1 7.0.3 GHSA-g4vj-cjjj-v7hg
System.Security.Cryptography.Xml 10.0.3 10.0.6 CVE-2026-33116, CVE-2026-26171

CG Work Items Resolved

CG Work Items Not Addressed Here

  • AB#10474, AB#10475, AB#10482 (.NET SDK security - 8.0/9.0/10.0): SDK versions in \�ng/common\ templates use \�ersion: X.0.x\ with rollforward, so patched SDKs (8.0.126, 9.0.116, 10.0.106) are picked up automatically.
  • AB#10440, AB#10441, AB#10442 (NuGet 6.11.0/6.14.0): Transitive via the SDK; resolved when patched SDKs are used.
  • AB#10247 (Microsoft.Guardian.Cli 0.109.0): Installed by the 1ES/Guardian pipeline task, not a repo dependency.

Notes

  • NuGet 7.0.3 stays within the same patch band, respecting the existing constraint: Don't version higher than what's available in the toolset SDK.
  • The \SystemSecurityCryptographyXmlPackageVersion\ in \Version.Details.props\ is normally managed by Maestro dependency flow from dotnet/runtime. The next flow will bring >= 10.0.6 since the fix is already published.

- NuGet.* 7.0.1 -> 7.0.3 (GHSA-g4vj-cjjj-v7hg)
- System.Security.Cryptography.Xml 10.0.3 -> 10.0.6 (CVE-2026-33116, CVE-2026-26171)
@missymessa missymessa force-pushed the dev/mjanecke/fix-cg-alerts-april-2026 branch from 4a48ac9 to 9428c00 Compare April 20, 2026 17:56
@missymessa missymessa enabled auto-merge (squash) April 20, 2026 17:58
@missymessa missymessa merged commit a5b2c04 into main Apr 20, 2026
8 of 9 checks passed
@missymessa missymessa deleted the dev/mjanecke/fix-cg-alerts-april-2026 branch April 20, 2026 18:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants