Bump SourceLink past CVE-2026-62900, and System.IO.Hashing with it (#3210)
NuGet audit started failing every build yesterday: error NU1902: Package 'Microsoft.Build.Tasks.Git' 10.0.201 has a known moderate severity vulnerability GHSA-23fw-v26w-5fgq was published on 2026-09-08. We pull Build.Tasks.Git transitively via Microsoft.SourceLink.GitHub, which was pinned at 10.0.201 - and the advisory lists the whole 10.0.200-10.0.204 band as affected with no patched version in that band, so there is nothing to move to inside it. Going to 10.0.401 takes us past every affected range. That in turn wants System.IO.Hashing 10.0.12, where we pinned 10.0.5, so without bumping that too the restore trades NU1902 for NU1605. Note this is consumer-visible: System.IO.Hashing is a real dependency of the library, so the floor it declares moves from 10.0.5 to 10.0.12 on every target framework. SourceLink itself is build-time only and stays out of the package's dependency groups. SourceLink 10.0.112 would have fixed the advisory without touching System.IO.Hashing at all - it has no dependency on it - but that means moving back a servicing band, so it is only the answer if the floor bump is unwelcome.
M
Marc Gravell committed
46615fc73d4ed84a0f8183e6b2adb090e659e365
Parent: 4ec7273
Committed by GitHub <noreply@github.com>
on 9/9/2026, 10:54:16 AM