release: 1.0.2 — security patch (System.Security.Cryptography.Xml 8.0.4) - #26
Merged
Merged
Conversation
Bumps all eight packable projects 1.0.1 -> 1.0.2, records the release in the changelog, and advances the README status line. Patch rather than minor: no wire-format change and no public API change. Every 1.0.1 envelope decodes identically, so this is a drop-in over 1.0.1. The release exists to ship the System.Security.Cryptography.Xml 8.0.3 -> 8.0.4 fix from #24. 1.0.1 declares the vulnerable version as a direct dependency of the core package, and .Aws, .AzureKeyVault, .Cli, .Fips, .OpenTelemetry, .Redis and .Testing all depend on the core -- so all eight published packages currently resolve a library carrying five HIGH-severity advisories. Upgrading is recommended for every consumer. Note this repository has no release automation: there is no release.yml and nothing in CI pushes to NuGet, so v1.0.0 and v1.0.1 were published by hand. This PR prepares the release; packing and pushing remain a manual step. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Prepares the security release for the fix merged in #24.
Why this matters
PostQuantum.DataProtection 1.0.1declaresSystem.Security.Cryptography.Xml 8.0.3as a direct dependency, and.Aws,.AzureKeyVault,.Cli,.Fips,.OpenTelemetry,.Redisand.Testingall depend on the core package. So all eight published packages currently resolve a library affected by five HIGH-severity advisories:GHSA-23rf-6693-g89p · GHSA-8q5v-6pqq-x66h · GHSA-cvvh-rhrc-wg4q · GHSA-g8r8-53c2-pm3f · GHSA-mmjf-rqrv-855v
Until 1.0.2 ships, every consumer of any of those eight packages is exposed. The fix is already on main; it just isn't on nuget.org.
What's here
Version, plusFileVersion/InformationalVersionwhere present)Patch, not minor — no wire-format change, no public API change. Every 1.0.1 envelope decodes identically; drop-in over 1.0.1.
Known state at time of release
Release 1.0.0andRelease 1.0.1were cut from that same red build.This does not publish anything
This repository has no release automation — no
release.yml, and nothing in CI pushes to NuGet.v1.0.0andv1.0.1were published by hand. After merging you'll need to tagv1.0.2, thendotnet packanddotnet nuget pushthe eight packages yourself.Worth considering a
release.ymlmodelled on the one inpostquantum-file-encryption— its version gate caught a genuine docs/version mismatch during the 1.7.0 release today, before anything was published.🤖 Generated with Claude Code