Skip to content

Bump Microsoft.Bcl.Memory from 9.0.0 to 9.0.14 to address GHSA-73j8-2gch-69rq#649

Open
setoy wants to merge 1 commit intopasswordless-lib:mainfrom
setoy:fix/bump-microsoft-bcl-memory-9-0-14
Open

Bump Microsoft.Bcl.Memory from 9.0.0 to 9.0.14 to address GHSA-73j8-2gch-69rq#649
setoy wants to merge 1 commit intopasswordless-lib:mainfrom
setoy:fix/bump-microsoft-bcl-memory-9-0-14

Conversation

@setoy
Copy link
Copy Markdown

@setoy setoy commented Mar 12, 2026

This PR updates Microsoft.Bcl.Memory in Directory.Packages.props from 9.0.0 to 9.0.14.

Reason:

  • 9.0.0 is flagged by GitHub/NuGet vulnerability auditing
  • Consumers of Fido2.AspNet / Fido2.Models can currently inherit the vulnerable transitive version
  • 9.0.14 stays within the existing 9.x line and should be a low-risk patch update

This should help downstream projects that treat vulnerability warnings as errors.

Rel: GHSA-73j8-2gch-69rq

@SveinnB
Copy link
Copy Markdown

SveinnB commented Mar 18, 2026

Hey @abergs, would you have time to take a look at this? It's a straightforward patch bump to address a known vulnerability (GHSA-73j8-2gch-69rq), so hopefully a quick review. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants