Skip to content

Commit 6575743

Browse files
authored
Changes: dotnet/msbuild@v17.9.5...v17.10.4 Updates $(MSBuildPackageReferenceVersion) to the latest VS 2022 LTS. This new package version brings in System.Security.Cryptography.Xml v8.0.0 as a transitive dependency, and as such the explicitl v7.0.1 package reference should no longer be necessary. An explicit package reference has been added for System.Formats.Asn1 v8.0.1 to address CVE-2024-38095.
1 parent 7ec795c commit 6575743

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

src/Microsoft.Android.Build.BaseTasks/MSBuildReferences.projitems

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,7 @@
44
<Project>
55
<!--Import this file in projects needing to reference Microsoft.Build.*.dll -->
66
<PropertyGroup>
7-
<MSBuildPackageReferenceVersion Condition=" '$(MSBuildPackageReferenceVersion)' == '' ">17.9.5</MSBuildPackageReferenceVersion>
8-
<SystemSecurityCryptographyXmlVersion Condition=" '$(SystemSecurityCryptographyXmlVersion)' == '' ">7.0.1</SystemSecurityCryptographyXmlVersion>
7+
<MSBuildPackageReferenceVersion Condition=" '$(MSBuildPackageReferenceVersion)' == '' ">17.10.4</MSBuildPackageReferenceVersion>
98
<LibZipSharpVersion Condition=" '$(LibZipSharpVersion)' == '' " >3.3.0</LibZipSharpVersion>
109
<MonoUnixVersion>7.1.0-final.1.21458.1</MonoUnixVersion>
1110
</PropertyGroup>
@@ -15,7 +14,8 @@
1514
<PackageReference Include="Microsoft.Build.Framework" Version="$(MSBuildPackageReferenceVersion)" />
1615
<PackageReference Include="Microsoft.Build.Tasks.Core" Version="$(MSBuildPackageReferenceVersion)" />
1716
<PackageReference Include="Microsoft.Build.Utilities.Core" Version="$(MSBuildPackageReferenceVersion)" />
18-
<PackageReference Include="System.Security.Cryptography.Xml" Version="$(SystemSecurityCryptographyXmlVersion)" />
17+
<!-- Explicitly update the System.Formats.Asn1 transitive dependency of Microsoft.Build to address https://github.com/advisories/GHSA-447r-wph3-92pm -->
18+
<PackageReference Include="System.Formats.Asn1" Version="8.0.1" />
1919
<PackageReference Include="K4os.Compression.LZ4" Version="1.1.11" />
2020
<PackageReference Include="Xamarin.LibZipSharp" Version="$(LibZipSharpVersion)" GeneratePathProperty="true" />
2121
<PackageReference Include="Mono.Unix" Version="$(MonoUnixVersion)" GeneratePathProperty="true" />

0 commit comments

Comments
 (0)