Skip to content

Conversation

@Numpsy
Copy link
Contributor

@Numpsy Numpsy commented Oct 16, 2025

The versions its currently using are listed as suffering from GHSA-w3q9-fxm7-j8fq.

When I try to build the current code locally, it fails to build because the build has warnings-as-errors enabled, and NuGet package auditing flags up the CVE with a build warning..

So - maybe the dependencies need to be updated to the fixed versions?

The versions its currently using are listed as suffering from GHSA-w3q9-fxm7-j8fq.

When I try to build the current code locally, it fails to build because the build has warnings-as-errors enabled, and NuGet package auditing flags up the CVE as an error.

So - maybe the dependencies need to be updated to the fixed versions?
@Numpsy Numpsy changed the title Update Microsoft.Build dependencies Update Microsoft.Build dependencies to pick up fix for CVE-2025-55247 Oct 16, 2025
@knocte knocte merged commit d1e9fae into fsprojects:master Oct 28, 2025
6 checks passed
@knocte
Copy link
Collaborator

knocte commented Oct 28, 2025

Thanks!

@knocte knocte mentioned this pull request Oct 28, 2025
@Numpsy Numpsy deleted the update_msbuild branch October 28, 2025 09:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants