fix(build): pin dep for clear audit - #80
Merged
Merged
Conversation
Signed-off-by: Samantha Coyle <sam@diagrid.io>
yaron2
approved these changes
Sep 17, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR description
dotnet restorefails on master withNU1902: Package 'Microsoft.Build.Tasks.Git' 10.0.300 has a known moderate severity vulnerability(GHSA-23fw-v26w-5fgq), whichTreatWarningsAsErrorsturns into a hard restore failure for both packable projects. Since the restore step gates every downstream job, nothing builds, tests, packs or publishes until this clears — including thev1.2.0release.The earlier bump of
Microsoft.SourceLink.GitHubto 10.0.401 was correct but incomplete. SourceLink 10.0.401 does ask forBuild.Tasks.Git10.0.401, but that package also arrives from the SDK itself at 10.0.300, and since nothing in this repo references it directly there was noPackageVersionentry for central transitive pinning to raise. This adds one, in lockstep with the SourceLink pin it belongs to.This is also why the failure is CI-only and did not reproduce locally:
global.jsonsetsrollForward: latestFeature, so CI rolls from the declared 10.0.100 up to SDK 10.0.401, and it is that band which contributes the vulnerable 10.0.300. A local 10.0.1xx SDK never sees it.Per the advisory, 10.0.300–10.0.301 are affected with 10.0.303 the first patched release in that band; the 10.0.4xx band is unaffected. Pinning to 10.0.401 rather than 10.0.303 keeps the two SourceLink-related packages on the same version.
Verification
Pinning to a deliberately different version confirms the central entry actually governs resolution rather than merely agreeing with it:
10.0.303→dotnet nuget whyresolvesMicrosoft.Build.Tasks.Git (v10.0.303)10.0.401→ resolvesMicrosoft.Build.Tasks.Git (v10.0.401)Then, with the pin at 10.0.401:
dotnet restorereports zero NU1902/NU1903 audit errors,dotnet build -c Releasesucceeds with 0 warnings and 0 errors, the identity tests pass 131/131 on each of net8.0, net9.0 and net10.0, anddotnet packproduces all four packages.