-
Notifications
You must be signed in to change notification settings - Fork 5.3k
[CG] Bump Microsoft.IO.Redist to 6.0.1 #106102
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
CG was flagging ILLink.Tasks and Microsoft.NETCore.Platforms as pulling in an older version of Microsoft.IO.Redist. This change pins the version we use to clear the alert.
|
Tagging subscribers to this area: @dotnet/area-infrastructure-libraries |
|
Do we need to backport this change? |
sbomer
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
For ILLink.Tasks, this is pulled in as a transitive dependency of Microsoft.Build.Tasks.Core. Could we fix it by bumping MicrosoftBuildVersion to pick up dotnet/msbuild#10375?
Has that shipped yet? I didn't think it did. |
|
Let's wait for MSBuild to move first. |
agocke
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hold until we decide what to do for MSBuild
|
consider porting fix to 8.0/9.0 branches since it also shows on CG alerts there |
This is causing CG errors, need to resolve ASAP
|
cc @ericstj |
|
We actually do need to push this forward and backport to release/8.0 and release/9.0. It's blocking SDL signoff for 9.0 and it's not clear how when MSBuild is going to bump. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We shouldn't need this. We don't reference the Microsoft.IO.Redist package at all in main.
That was fixed with the PackageDownloadAndReference to only reference MSBuild itself.
@steveisok main has no CG alerts for this package. I only see them in 8.0 and 9.0. Perhaps we should consider backporting a portion of the audit change from main so that we don't end up chasing these alerts for build tasks.
Which change are you referring to? |
|
This one: #107639 I ported it back to 9.0. We can do something similar for 8.0, though we can't enable audit there. |
CG was flagging ILLink.Tasks and Microsoft.NETCore.Platforms as pulling in an older version of Microsoft.IO.Redist. This change pins the version we use to clear the alert.