SIGN IN SIGN UP

Bump SourceLink past CVE-2026-62900, and System.IO.Hashing with it (#3210)

NuGet audit started failing every build yesterday:

  error NU1902: Package 'Microsoft.Build.Tasks.Git' 10.0.201 has a known
  moderate severity vulnerability

GHSA-23fw-v26w-5fgq was published on 2026-09-08. We pull Build.Tasks.Git
transitively via Microsoft.SourceLink.GitHub, which was pinned at 10.0.201 - and
the advisory lists the whole 10.0.200-10.0.204 band as affected with no patched
version in that band, so there is nothing to move to inside it.

Going to 10.0.401 takes us past every affected range. That in turn wants
System.IO.Hashing 10.0.12, where we pinned 10.0.5, so without bumping that too
the restore trades NU1902 for NU1605.

Note this is consumer-visible: System.IO.Hashing is a real dependency of the
library, so the floor it declares moves from 10.0.5 to 10.0.12 on every target
framework. SourceLink itself is build-time only and stays out of the package's
dependency groups.

SourceLink 10.0.112 would have fixed the advisory without touching
System.IO.Hashing at all - it has no dependency on it - but that means moving
back a servicing band, so it is only the answer if the floor bump is unwelcome.
M
Marc Gravell committed
46615fc73d4ed84a0f8183e6b2adb090e659e365
Parent: 4ec7273
Committed by GitHub <noreply@github.com> on 9/9/2026, 10:54:16 AM