From 475ebe4f14e015dd57563dbe659f54e7d343b503 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 14 Apr 2026 23:36:38 +0000 Subject: [PATCH 1/2] Bump System.Security.Cryptography.Xml from 8.0.2 to 8.0.3 --- updated-dependencies: - dependency-name: System.Security.Cryptography.Xml dependency-version: 8.0.3 dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- Directory.Packages.props | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Directory.Packages.props b/Directory.Packages.props index 3374fa244c..00e9816381 100644 --- a/Directory.Packages.props +++ b/Directory.Packages.props @@ -53,7 +53,7 @@ - + From 8b52b477d7861d758de2ffa32af28c09d5af00dc Mon Sep 17 00:00:00 2001 From: martincostello Date: Wed, 15 Apr 2026 11:48:25 +0100 Subject: [PATCH 2/2] [WCF] Update System.Security.Cryptography.Xml Bump minimum version for `net8.0`, `net9.0` and `net10.0`. --- Directory.Packages.props | 5 ++++- src/OpenTelemetry.Instrumentation.Wcf/CHANGELOG.md | 5 +++++ 2 files changed, 9 insertions(+), 1 deletion(-) diff --git a/Directory.Packages.props b/Directory.Packages.props index 00e9816381..1c117caf86 100644 --- a/Directory.Packages.props +++ b/Directory.Packages.props @@ -53,7 +53,7 @@ - + @@ -62,14 +62,17 @@ + + + diff --git a/src/OpenTelemetry.Instrumentation.Wcf/CHANGELOG.md b/src/OpenTelemetry.Instrumentation.Wcf/CHANGELOG.md index 056e52659b..dbb010a123 100644 --- a/src/OpenTelemetry.Instrumentation.Wcf/CHANGELOG.md +++ b/src/OpenTelemetry.Instrumentation.Wcf/CHANGELOG.md @@ -5,6 +5,11 @@ * Updated OpenTelemetry core component version(s) to `1.15.2`. ([#4080](https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4080)) +* Update `System.Security.Cryptography.Xml` dependency versions for .NET 8, 9 and + 10 to pick up fixes for [GHSA-w3x6-4m5h-cxqf](https://github.com/dotnet/runtime/security/advisories/GHSA-w3x6-4m5h-cxqf) + and [GHSA-37gx-xxp4-5rgx](https://github.com/dotnet/runtime/security/advisories/GHSA-37gx-xxp4-5rgx). + ([#4103](https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4103)) + ## 1.15.0-beta.1 Released 2026-Jan-21