Skip to content

deps(nuget): Bump Microsoft.Diagnostics.Tracing.TraceEvent from 3.1.30 to 3.2.5#49

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/Microsoft.Diagnostics.Tracing.TraceEvent-3.2.5
Closed

deps(nuget): Bump Microsoft.Diagnostics.Tracing.TraceEvent from 3.1.30 to 3.2.5#49
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/Microsoft.Diagnostics.Tracing.TraceEvent-3.2.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 18, 2026

Copy link
Copy Markdown
Contributor

Updated Microsoft.Diagnostics.Tracing.TraceEvent from 3.1.30 to 3.2.5.

Release notes

Sourced from Microsoft.Diagnostics.Tracing.TraceEvent's releases.

3.2.5

What's Changed

Full Changelog: microsoft/perfview@v3.2.4...v3.2.5

3.2.4

Security

This release contains security hardening fixes for a number of malformed-input parsing and path-traversal vulnerabilities:

  • Bounds-checking for malformed event payloads in the BPerf ULZ777 decompressor and event-record parser
  • Bounds-checking for malformed metadata in the GCDynamic, RegisteredTraceEventParser (TDH), Dynamic, and EventPipe V3 parsers
  • Bounds-checking for malformed PE CodeView and Resource directory entries
  • Path containment hardening for PDB extraction (zipped ETL + container PDBs), DiagSession resource extraction, R2R perf map writes, PdbScope module paths, and dynamic manifest writes
  • Path-traversal and command-execution hardening for Source Server lookups

What's Changed

Full Changelog: microsoft/perfview@v3.2.3...v3.2.4

3.2.3

What's Changed

New Contributors

Full Changelog: microsoft/perfview@v3.2.2...v3.2.3

3.2.2

What's Changed

Full Changelog: microsoft/perfview@v3.2.1...v3.2.2

3.2.1

Native and R2R Symbol Download and Parsing Now Available

As of this release, if you capture a trace using dotnet-trace collect-linux or record-trace, native and R2R symbols can now be downloaded and resolved at analysis time. All .NET symbols (both native and R2R) are available on the Microsoft Symbol Server. Additionally, many Azure Linux symbol files are available on the Microsoft Symbol Server. For those targeting other distros, PerfView and TraceEvent are capable of pulling those symbol files from local directories by adding a local symbol path pointing to the files.

Most of the work for this was completed in PerfView and TraceEvent 3.2.1 with the final required fixes present in this release.

What's Changed

Full Changelog: microsoft/perfview@v3.2.0...v3.2.1

3.2.0

What's Changed

New Contributors

Full Changelog: microsoft/perfview@v3.1.30...v3.2.0

Commits viewable in compare view.

@dependabot @github

dependabot Bot commented on behalf of github Jul 18, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, nuget. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@adsamcik

Copy link
Copy Markdown
Owner

@dependabot rebase

…0 to 3.2.5

---
updated-dependencies:
- dependency-name: Microsoft.Diagnostics.Tracing.TraceEvent
  dependency-version: 3.2.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 18, 2026

Copy link
Copy Markdown
Contributor Author

Looks like Microsoft.Diagnostics.Tracing.TraceEvent is no longer updatable, so this is no longer needed.

@dependabot
dependabot Bot force-pushed the dependabot/nuget/Microsoft.Diagnostics.Tracing.TraceEvent-3.2.5 branch from 09c1ac1 to 77102b1 Compare July 18, 2026 21:37
@dependabot dependabot Bot closed this Jul 18, 2026
@dependabot
dependabot Bot deleted the dependabot/nuget/Microsoft.Diagnostics.Tracing.TraceEvent-3.2.5 branch July 18, 2026 21:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant