Skip to content

Conversation

@nil4
Copy link

@nil4 nil4 commented Oct 16, 2025

Address high-severity vulnerabilities in MSBuild packages that Nuke depends on:

Fixes #1544

I confirm that the pull-request:

  • Follows the contribution guidelines
  • Is based on my own work
  • Is in compliance with my employer

@nil4
Copy link
Author

nil4 commented Oct 16, 2025

Resolves the following NuGet audit warnings observed when building Nuke:

Nuke.ProjectModel/Nuke.ProjectModel.csproj : warning NU1903: Package 'Microsoft.Build' 17.11.4 has a known high severity vulnerability, https://github.com/advisories/GHSA-w3q9-fxm7-j8fq
Nuke.ProjectModel/Nuke.ProjectModel.csproj : warning NU1903: Package 'Microsoft.Build' 17.12.6 has a known high severity vulnerability, https://github.com/advisories/GHSA-w3q9-fxm7-j8fq
Nuke.ProjectModel/Nuke.ProjectModel.csproj : warning NU1903: Package 'Microsoft.Build.Tasks.Core' 17.11.4 has a known high severity vulnerability, https://github.com/advisories/GHSA-h4j7-5rxr-p4wc
Nuke.ProjectModel/Nuke.ProjectModel.csproj : warning NU1903: Package 'Microsoft.Build.Tasks.Core' 17.11.4 has a known high severity vulnerability, https://github.com/advisories/GHSA-w3q9-fxm7-j8fq
Nuke.ProjectModel/Nuke.ProjectModel.csproj : warning NU1903: Package 'Microsoft.Build.Tasks.Core' 17.12.6 has a known high severity vulnerability, https://github.com/advisories/GHSA-h4j7-5rxr-p4wc
Nuke.ProjectModel/Nuke.ProjectModel.csproj : warning NU1903: Package 'Microsoft.Build.Tasks.Core' 17.12.6 has a known high severity vulnerability, https://github.com/advisories/GHSA-w3q9-fxm7-j8fq
Nuke.ProjectModel/Nuke.ProjectModel.csproj : warning NU1903: Package 'Microsoft.Build.Utilities.Core' 17.11.4 has a known high severity vulnerability, https://github.com/advisories/GHSA-w3q9-fxm7-j8fq
Nuke.ProjectModel/Nuke.ProjectModel.csproj : warning NU1903: Package 'Microsoft.Build.Utilities.Core' 17.12.6 has a known high severity vulnerability, https://github.com/advisories/GHSA-w3q9-fxm7-j8fq

@avidenic
Copy link
Contributor

Would love if this gets merged

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Consider upgrading vulnerable Microsoft.Build.Tasks.Core dependency

2 participants