Skip to content

deps: Bump Microsoft.Diagnostics.Tracing.TraceEvent from 3.2.3 to 3.2.4#58

Merged
st0o0 merged 1 commit into
mainfrom
dependabot/nuget/src/Microsoft.Diagnostics.Tracing.TraceEvent-3.2.4
Jul 5, 2026
Merged

deps: Bump Microsoft.Diagnostics.Tracing.TraceEvent from 3.2.3 to 3.2.4#58
st0o0 merged 1 commit into
mainfrom
dependabot/nuget/src/Microsoft.Diagnostics.Tracing.TraceEvent-3.2.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 25, 2026

Copy link
Copy Markdown
Contributor

Updated Microsoft.Diagnostics.Tracing.TraceEvent from 3.2.3 to 3.2.4.

Release notes

Sourced from Microsoft.Diagnostics.Tracing.TraceEvent's releases.

3.2.4

Security

This release contains security hardening fixes for a number of malformed-input parsing and path-traversal vulnerabilities:

  • Bounds-checking for malformed event payloads in the BPerf ULZ777 decompressor and event-record parser
  • Bounds-checking for malformed metadata in the GCDynamic, RegisteredTraceEventParser (TDH), Dynamic, and EventPipe V3 parsers
  • Bounds-checking for malformed PE CodeView and Resource directory entries
  • Path containment hardening for PDB extraction (zipped ETL + container PDBs), DiagSession resource extraction, R2R perf map writes, PdbScope module paths, and dynamic manifest writes
  • Path-traversal and command-execution hardening for Source Server lookups

What's Changed

Full Changelog: microsoft/perfview@v3.2.3...v3.2.4

Commits viewable in compare view.

@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Jun 25, 2026
@dependabot dependabot Bot force-pushed the dependabot/nuget/src/Microsoft.Diagnostics.Tracing.TraceEvent-3.2.4 branch 3 times, most recently from 24e467a to d291302 Compare July 5, 2026 08:50
@st0o0

st0o0 commented Jul 5, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot dependabot Bot force-pushed the dependabot/nuget/src/Microsoft.Diagnostics.Tracing.TraceEvent-3.2.4 branch from d291302 to dac904f Compare July 5, 2026 12:42
@st0o0

st0o0 commented Jul 5, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

---
updated-dependencies:
- dependency-name: Microsoft.Diagnostics.Tracing.TraceEvent
  dependency-version: 3.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/nuget/src/Microsoft.Diagnostics.Tracing.TraceEvent-3.2.4 branch from dac904f to cbc7a82 Compare July 5, 2026 13:02
@st0o0 st0o0 merged commit 7cfd0e8 into main Jul 5, 2026
5 checks passed
@st0o0 st0o0 deleted the dependabot/nuget/src/Microsoft.Diagnostics.Tracing.TraceEvent-3.2.4 branch July 5, 2026 14:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant