Skip to content

[release/8.0] Update System.Security.Cryptography.Xml in RepoTasks#66766

Open
wtgodbe wants to merge 2 commits into
release/8.0from
wtgodbe/xml8
Open

[release/8.0] Update System.Security.Cryptography.Xml in RepoTasks#66766
wtgodbe wants to merge 2 commits into
release/8.0from
wtgodbe/xml8

Conversation

@wtgodbe
Copy link
Copy Markdown
Member

@wtgodbe wtgodbe commented May 20, 2026

Fixes a CG alert

Updated System.Security.Cryptography.Xml package version to address CVE-2023-29331.
@wtgodbe wtgodbe requested a review from a team as a code owner May 20, 2026 19:42
Copilot AI review requested due to automatic review settings May 20, 2026 19:42
@dotnet-policy-service dotnet-policy-service Bot added this to the 8.0.x milestone May 20, 2026
@wtgodbe wtgodbe added the tell-mode Indicates a PR which is being merged during tell-mode label May 20, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aims to address a CodeQL/CG (component governance) security alert by explicitly updating the System.Security.Cryptography.Xml dependency used by the RepoTasks build tool project.

Changes:

  • Add an explicit PackageReference to System.Security.Cryptography.Xml in RepoTasks.csproj to mitigate CVE-2023-29331.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread eng/tools/RepoTasks/RepoTasks.csproj
@github-actions github-actions Bot added the area-infrastructure Includes: MSBuild projects/targets, build scripts, CI, Installers and shared framework label May 20, 2026
@dotnet-policy-service
Copy link
Copy Markdown
Contributor

Hey @dotnet/aspnet-build, looks like this PR is something you want to take a look at.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-infrastructure Includes: MSBuild projects/targets, build scripts, CI, Installers and shared framework tell-mode Indicates a PR which is being merged during tell-mode

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants