Skip to content

Bump System.Security.Cryptography.Xml to 10.0.6#13548

Open
SimonCropp wants to merge 1 commit intodotnet:mainfrom
SimonCropp:Bump-System.Security.Cryptography.Xml-to-10.0.6
Open

Bump System.Security.Cryptography.Xml to 10.0.6#13548
SimonCropp wants to merge 1 commit intodotnet:mainfrom
SimonCropp:Bump-System.Security.Cryptography.Xml-to-10.0.6

Conversation

@SimonCropp
Copy link
Copy Markdown
Contributor

@SimonCropp SimonCropp requested a review from a team as a code owner April 15, 2026 21:55
Copilot AI review requested due to automatic review settings April 15, 2026 21:55
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the pinned System.Security.Cryptography.Xml dependency version to address the GHSA-37gx-xxp4-5rgx advisory, aligning both the source-build dependency metadata and the centrally-managed package version property.

Changes:

  • Bump System.Security.Cryptography.Xml from 10.0.4 to 10.0.6 in eng/Version.Details.xml.
  • Bump SystemSecurityCryptographyXmlPackageVersion from 10.0.4 to 10.0.6 in eng/Version.Details.props.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
eng/Version.Details.xml Updates source-build dependency metadata to use System.Security.Cryptography.Xml 10.0.6.
eng/Version.Details.props Updates the central property that drives System.Security.Cryptography.Xml package version resolution.

@ViktorHofer
Copy link
Copy Markdown
Member

We usually need to coordinate runtime package updates with VS. Also, we keep all runtime package versions in sync, so everything currently on 10.0.4 should get updated to 10.0.6. @rainersigwald who is the best person to reach out on VS regarding updating to 10.0.6?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants