Skip to content

release: 1.0.2 — security patch (System.Security.Cryptography.Xml 8.0.4) - #26

Merged
systemslibrarian merged 1 commit into
mainfrom
release/1.0.2
Aug 19, 2026
Merged

systemslibrarian merged 1 commit into
mainfrom
release/1.0.2

Conversation

@systemslibrarian

Copy link
Copy Markdown
Owner

Prepares the security release for the fix merged in #24.

Why this matters

PostQuantum.DataProtection 1.0.1 declares System.Security.Cryptography.Xml 8.0.3 as a direct dependency, and .Aws, .AzureKeyVault, .Cli, .Fips, .OpenTelemetry, .Redis and .Testing all depend on the core package. So all eight published packages currently resolve a library affected by five HIGH-severity advisories:

GHSA-23rf-6693-g89p · GHSA-8q5v-6pqq-x66h · GHSA-cvvh-rhrc-wg4q · GHSA-g8r8-53c2-pm3f · GHSA-mmjf-rqrv-855v

Until 1.0.2 ships, every consumer of any of those eight packages is exposed. The fix is already on main; it just isn't on nuget.org.

What's here

  • All 8 packable projects 1.0.1 → 1.0.2 (Version, plus FileVersion/InformationalVersion where present)
  • CHANGELOG entry naming each advisory and its CVE
  • README status line

Patch, not minor — no wire-format change, no public API change. Every 1.0.1 envelope decodes identically; drop-in over 1.0.1.

Known state at time of release

  • CI coverage gate is red — 78.25% line / 69.32% branch against an 85%/75% target. Tracked in Coverage has drifted to 78.25% line / 69.32% branch (gate expects 85% / 75%) #25. This is pre-existing drift, not a regression: restore failed on every main commit from 2026-06-04 onward, so the gate has been unenforceable for two and a half months. All 108 tests pass with 0 skipped.
  • Both Release 1.0.0 and Release 1.0.1 were cut from that same red build.

This does not publish anything

This repository has no release automation — no release.yml, and nothing in CI pushes to NuGet. v1.0.0 and v1.0.1 were published by hand. After merging you'll need to tag v1.0.2, then dotnet pack and dotnet nuget push the eight packages yourself.

Worth considering a release.yml modelled on the one in postquantum-file-encryption — its version gate caught a genuine docs/version mismatch during the 1.7.0 release today, before anything was published.

🤖 Generated with Claude Code

Bumps all eight packable projects 1.0.1 -> 1.0.2, records the release in the
changelog, and advances the README status line.

Patch rather than minor: no wire-format change and no public API change. Every
1.0.1 envelope decodes identically, so this is a drop-in over 1.0.1.

The release exists to ship the System.Security.Cryptography.Xml 8.0.3 -> 8.0.4
fix from #24. 1.0.1 declares the vulnerable version as a direct dependency of the
core package, and .Aws, .AzureKeyVault, .Cli, .Fips, .OpenTelemetry, .Redis and
.Testing all depend on the core -- so all eight published packages currently
resolve a library carrying five HIGH-severity advisories. Upgrading is
recommended for every consumer.

Note this repository has no release automation: there is no release.yml and
nothing in CI pushes to NuGet, so v1.0.0 and v1.0.1 were published by hand. This
PR prepares the release; packing and pushing remain a manual step.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@systemslibrarian
systemslibrarian merged commit a3c03e9 into main Aug 19, 2026
4 of 5 checks passed
@systemslibrarian
systemslibrarian deleted the release/1.0.2 branch August 19, 2026 22:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant