fix: update SourceLink to resolve badge update audit failure - #6
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
badge updatecould not restore because the inherited SourceLink dependency resolved Microsoft.Build.Tasks.Git 10.0.300, which triggers NU1902 for CVE-2026-62900 under warnings-as-errors. Update the central Microsoft.SourceLink.GitHub pin to 10.0.303; Microsoft.SourceLink.Common and Microsoft.Build.Tasks.Git now also resolve to 10.0.303. No other SourceLink or Git task pins exist.Validation on .NET SDK 10.0.303 (Windows):
dotnet run --file tools/badgesmith.cs -- badge update --helpbefore the change; the same command now passes.dotnet restore BadgeSmith.slnpasses.dotnet build BadgeSmith.sln --no-restore --configuration Releasepasses with zero warnings and errors.dotnet list BadgeSmith.sln package --vulnerable --include-transitiveand the equivalent audit fortools/badgesmith.csreport no vulnerable packages.This build-dependency patch changes no HTTP or HMAC contract. Consumers can update their pinned action commit to the merged master SHA without redeploying api.localstackfor.net. No production deployment is required or performed.