Skip to content

[main] Source code updates from dotnet/dotnet#20058

Open
dotnet-maestro[bot] wants to merge 9 commits into
mainfrom
darc-main-b65a9935-28e2-420d-a350-5ffd0a001c93
Open

[main] Source code updates from dotnet/dotnet#20058
dotnet-maestro[bot] wants to merge 9 commits into
mainfrom
darc-main-b65a9935-28e2-420d-a350-5ffd0a001c93

Conversation

@dotnet-maestro

@dotnet-maestro dotnet-maestro Bot commented Jul 11, 2026

Copy link
Copy Markdown
Contributor

Note

This is a codeflow update. It may contain both source code changes from
the VMR
as well as dependency updates. Learn more here.

This pull request brings the following source code changes

From https://github.com/dotnet/dotnet

Updated Dependencies

Associated changes in source repos

Diff the source with this PR branch
darc vmr diff --name-only https://github.com/dotnet/dotnet:cb8306a63c5cf24e9381108a3a9eb58907fd0f60..https://github.com/dotnet/fsharp:darc-main-b65a9935-28e2-420d-a350-5ffd0a001c93

dotnet-maestro Bot added 2 commits July 11, 2026 02:11
Updated Dependencies:
Microsoft.Build, Microsoft.Build.Framework, Microsoft.Build.Tasks.Core, Microsoft.Build.Utilities.Core (Version 18.10.0-1.26359.10 -> 18.10.0-preview-26357-08)
[[ commit created by automation ]]
@github-actions

Copy link
Copy Markdown
Contributor

✅ No release notes required

@github-actions github-actions Bot added the AI-Tooling-Check-Bypassed Tooling check: non-fork PR, not diff-analyzed label Jul 11, 2026
dotnet-maestro Bot added 3 commits July 14, 2026 02:07
No dependency updates to commit
[[ commit created by automation ]]
No dependency updates to commit
[[ commit created by automation ]]
No dependency updates to commit
[[ commit created by automation ]]
Copilot AI and others added 4 commits July 21, 2026 10:47
The codeflow update to Microsoft.Build.* now transitively pulls
System.Security.Cryptography.Xml 10.0.8 (newly flagged by GHSA advisories,
patched in 10.0.10) on .NET, and Microsoft.CodeAnalysis.Test.Resources.Proprietary
-> NETStandard.Library 1.6.1 pulls vulnerable System.Net.Http 4.3.0 and
System.Text.RegularExpressions 4.3.0 on net472.

- Bump System.Security.Cryptography.Xml override to 10.0.10 (Version.Details).
- Add .NET-only Cryptography.Xml overrides in fsc/fsi/FSharp.Build.UnitTests
  (net472 excluded: no such transitive there and its deps conflict with
  System.ValueTuple). These cascade to Microsoft.FSharp.Compiler and FSharpSuite.Tests.
- Override the net472 System.Net.Http/System.Text.RegularExpressions facades to
  patched 4.3.4/4.3.1 in FSharp.Test.Utilities.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…e2-420d-a350-5ffd0a001c93

# Conflicts:
#	eng/Version.Details.props
#	eng/Version.Details.xml
StreamJsonRpc 2.25.29 pulls MessagePack transitively; some restore
environments resolve the vulnerable 2.5.198 (< 2.5.301 patched line),
tripping NuGetAudit warnings-as-errors in FSharp.Compiler.LanguageServer.Tests.
Add an explicit direct reference at 2.5.302 (StreamJsonRpc's own minimum,
already patched) so the resolved version is deterministic everywhere.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
A merge conflict resolution left a stray </Dependency> closing tag after
Microsoft.Build.Utilities.Core, making the XML invalid and failing the
Maestro Version.Details.props Validation and Codeflow verification checks.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AI-Tooling-Check-Bypassed Tooling check: non-fork PR, not diff-analyzed

Projects

Status: New

Development

Successfully merging this pull request may close these issues.

1 participant