Skip to content

Bump Microsoft.SourceLink.GitHub from 10.0.301 to 10.0.400 - #312

Merged
Chris-Wolfgang merged 2 commits into
mainfrom
dependabot/nuget/Microsoft.SourceLink.GitHub-10.0.400
Aug 19, 2026
Merged

Chris-Wolfgang merged 2 commits into
mainfrom
dependabot/nuget/Microsoft.SourceLink.GitHub-10.0.400

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 15, 2026

Copy link
Copy Markdown
Contributor

Updated Microsoft.SourceLink.GitHub from 10.0.301 to 10.0.400.

Release notes

Sourced from Microsoft.SourceLink.GitHub's releases.

10.0.400

You can build .NET 10.0 from the repository by cloning the release tag v10.0.400 and following the build instructions in the main README.md.

Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.

Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023

10.0.303

You can build .NET 10.0 from the repository by cloning the release tag v10.0.303 and following the build instructions in the main README.md.

Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.

Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023

10.0.302

You can build .NET 10.0 from the repository by cloning the release tag v10.0.302 and following the build instructions in the main README.md.

Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.

Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023

Commits viewable in compare view.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

---
updated-dependencies:
- dependency-name: Microsoft.SourceLink.GitHub
  dependency-version: 10.0.400
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 15, 2026
@dependabot
dependabot Bot requested a review from Chris-Wolfgang as a code owner August 15, 2026 07:04
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 15, 2026
@Chris-Wolfgang
Chris-Wolfgang merged commit a504b8b into main Aug 19, 2026
15 checks passed
@Chris-Wolfgang
Chris-Wolfgang deleted the dependabot/nuget/Microsoft.SourceLink.GitHub-10.0.400 branch August 19, 2026 15:45
Chris-Wolfgang added a commit that referenced this pull request Aug 20, 2026
Security PATCH round. Zero runtime behaviour changes to
Wolfgang.TryPattern; every diff since v0.4.0 is workflow YAML,
analyzer packages, or test-only files.

Highlights (full detail in CHANGELOG):

- SHA-pin all workflow actions to fleet-standard commit SHAs (+61
  Scorecard PinnedDependenciesID alerts resolved).
- Narrow semgrep-sast.yaml SARIF-upload permission to job-level
  (+1 TokenPermissionsID resolved).
- Add durable jq SARIF filter in scorecard.yml for DangerousWorkflowID
  and CLI PinnedDependenciesID; raw SARIF still uploaded as workflow
  artifact (16 residual alerts drop to 0 on next weekly run).
- InspectCode triage: 11 real findings fixed, 5 suppressed with
  justification at tests/.editorconfig.
- Dependency bumps: SonarAnalyzer.CSharp 10.31→10.32,
  Microsoft.SourceLink.GitHub 10.0.301→10.0.400,
  Meziantou.Analyzer 3.0.125→3.0.156.

Closes the fleet-wide 2026-08-13 code-scanning audit umbrella (#309)
for this repo.

Refs: #309, #311, #312, #314, #315, #316, #318

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant