Skip to content

fix(ci): unblock main — SourceLink 10.0.401 + IDE0370 - #193

Merged
Tiberriver256 merged 1 commit into
mainfrom
fix/ci-sourcelink-ide0370
Sep 14, 2026
Merged

Tiberriver256 merged 1 commit into
mainfrom
fix/ci-sourcelink-ide0370

Conversation

@Tiberriver256

Copy link
Copy Markdown
Owner

Summary

Main (and every Dependabot PR based on it) is red because Cake Restore/Build fails for two independent reasons:

  1. NU1902 (restore) — Microsoft.SourceLink.GitHub 10.0.300 pulls Microsoft.Build.Tasks.Git 10.0.300, which is flagged by GHSA-23fw-v26w-5fgq / CVE-2026-62900. With TreatWarningsAsErrors, restore fails. Introduced by merging Bump Microsoft.SourceLink.GitHub from 10.0.102 to 10.0.300 #176; advisory published 2026-09-08.
  2. IDE0370 (compile) — unnecessary ! on JsonValue.Create(...) in ODataQueryOptionsDocumentFilter.cs becomes an error under AnalysisLevel=latest + TreatWarningsAsErrors (from the Health TOP5: deps, quality gates, ValidationHarness in CI, multi-target, hygiene #177 health work).

Evidence: local dotnet cake --target=Build on current main fails with NU1902; after SourceLink-only bump, restore passes and build fails IDE0370. Both fixed here → Build/Test/coverage/Pack succeed locally (17 tests, ~34% coverage ≥ 30% gate).

CodeQL Analyze fails for the same autobuild/restore reason.

Changes

  • Bump Microsoft.SourceLink.GitHub 10.0.300 → 10.0.401 in Source/Directory.Build.props and the project Update
  • Drop four unnecessary null-forgiving operators (IDE0370)

After merge

Rebase/rerun Dependabot PRs. Expected to go green (patch/minor, non-major):

Do not merge majors without approval: #179 checkout v7, #181 setup-dotnet v6, #188 MinVer 8, plus older #152/#162.

Test plan

Bump Microsoft.SourceLink.GitHub to 10.0.401 so restore no longer fails NU1902 (GHSA-23fw-v26w-5fgq via Microsoft.Build.Tasks.Git 10.0.300).

Remove unnecessary null-forgiving operators that IDE0370 treats as errors under TreatWarningsAsErrors.
@Tiberriver256
Tiberriver256 merged commit 2a0df5f into main Sep 14, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant