Skip to content

Bump Microsoft.Bcl.Memory from 9.0.0 to 9.0.14 to address GHSA-73j8-2gch-69rq#649

Merged
abergs merged 1 commit intopasswordless-lib:mainfrom
setoy:fix/bump-microsoft-bcl-memory-9-0-14
Apr 6, 2026
Merged

Bump Microsoft.Bcl.Memory from 9.0.0 to 9.0.14 to address GHSA-73j8-2gch-69rq#649
abergs merged 1 commit intopasswordless-lib:mainfrom
setoy:fix/bump-microsoft-bcl-memory-9-0-14

Conversation

@setoy
Copy link
Copy Markdown
Contributor

@setoy setoy commented Mar 12, 2026

This PR updates Microsoft.Bcl.Memory in Directory.Packages.props from 9.0.0 to 9.0.14.

Reason:

  • 9.0.0 is flagged by GitHub/NuGet vulnerability auditing
  • Consumers of Fido2.AspNet / Fido2.Models can currently inherit the vulnerable transitive version
  • 9.0.14 stays within the existing 9.x line and should be a low-risk patch update

This should help downstream projects that treat vulnerability warnings as errors.

Rel: GHSA-73j8-2gch-69rq

@SveinnB
Copy link
Copy Markdown

SveinnB commented Mar 18, 2026

Hey @abergs, would you have time to take a look at this? It's a straightforward patch bump to address a known vulnerability (GHSA-73j8-2gch-69rq), so hopefully a quick review. Thanks!

@abergs abergs merged commit fb78713 into passwordless-lib:main Apr 6, 2026
1 check passed
@setoy setoy deleted the fix/bump-microsoft-bcl-memory-9-0-14 branch April 6, 2026 11:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants