-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[release/9.0.2xx] Update dependencies from nuget/nuget.client #45526
[release/9.0.2xx] Update dependencies from nuget/nuget.client #45526
Conversation
…6.13.0.100 Microsoft.Build.NuGetSdkResolver , NuGet.Build.Tasks , NuGet.Build.Tasks.Console , NuGet.Build.Tasks.Pack , NuGet.CommandLine.XPlat , NuGet.Commands , NuGet.Common , NuGet.Configuration , NuGet.Credentials , NuGet.DependencyResolver.Core , NuGet.Frameworks , NuGet.LibraryModel , NuGet.Localization , NuGet.Packaging , NuGet.ProjectModel , NuGet.Protocol , NuGet.Versioning From Version 6.13.0-rc.98 -> To Version 6.13.0-rc.100
I'm a bit confused on this one. The helix image we claim to be using should have 17.12 on it but we're getting STJ errors: Helix image: windows.amd64.vs2022.pre report as 17.12-p4 @rainersigwald @nkolev92 I assume nuget updated their STJ version. I'm not sure I understand why it's failing though if 17.12 is used. |
I would've expected this to work yeah. @zivkan Can you please take a look? |
Both System.Text.Json 8.0.5 and VS 17.12 preview 4 came out in October, so there's a good chance that the VS preview did not include the fixed version. Looking at https://helix.dot.net/, I don't see evidence that the windows.amd64.vs2022.pre image explicitly installs the .NET SDK or runtime. I assume it gets the .NET runtime that VS ships. According to dnceng's VS upgrade schedule, they rolled out 17.12 preview 4 on the 13th of November (the day that 17.12 GA was released 😕 ), and 17.13 preview 1 was supposed to be in the image since the 4th of December. But evidently that hasn't happened yet. @marcpopMSFT is the sdk repo able to temporarily switch to the windows.amd64.vs2022.pre.scout image? it has 17.13 preview 1. Alternatively, the windows.vs2022.scount.amd64.open image has 17.12.0 The only other options I can think of are NuGet to revert again, and start getting CG alerts again, or nag dnceng to find out what's going on. The last "ask mode" date for 17.13 isn't far off, so if we revert there's a chance we'll ship a nuget.exe with a vulnerable version of system.text.json in it, which isn't a good outcome for anyone. |
Ahh, maybe it wasn't fixed in preview 4 yet. Let's try the scouting version of the helix image and see if it works. |
This pull request updates the following dependencies
From /~https://github.com/nuget/nuget.client