From 159b103366cab9089da1f4c0497bb88cc91a1468 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 12 Jun 2026 00:09:15 +0000 Subject: [PATCH 1/3] Bump MessagePack from 2.5.198 to 2.5.301 --- updated-dependencies: - dependency-name: MessagePack dependency-version: 2.5.301 dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- .../Neolution.Extensions.Caching.Distributed.csproj | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/Neolution.Extensions.Caching.Distributed/Neolution.Extensions.Caching.Distributed.csproj b/src/Neolution.Extensions.Caching.Distributed/Neolution.Extensions.Caching.Distributed.csproj index 446a296..a9a10cb 100644 --- a/src/Neolution.Extensions.Caching.Distributed/Neolution.Extensions.Caching.Distributed.csproj +++ b/src/Neolution.Extensions.Caching.Distributed/Neolution.Extensions.Caching.Distributed.csproj @@ -7,7 +7,7 @@ - + From 9231a49ee1425c6e4117cb5cbc99eaf3005a43cc Mon Sep 17 00:00:00 2001 From: Sandro Ciervo Date: Tue, 4 Aug 2026 11:00:47 +0000 Subject: [PATCH 2/3] Bump MessagePack from 2.5.198 to 2.5.302 Retarget the Dependabot bump from 2.5.301 to 2.5.302: upstream notes that 2.5.301 is missing a fix from 2.5.205 and recommends 2.5.302, which combines all security fixes. Also apply the bump to Neolution.Extensions.Caching.RedisHybrid, which referenced the same vulnerable 2.5.198 but was not covered by the original Dependabot PR. Co-Authored-By: Claude Opus 5 (1M context) --- .../Neolution.Extensions.Caching.Distributed.csproj | 2 +- .../Neolution.Extensions.Caching.RedisHybrid.csproj | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/src/Neolution.Extensions.Caching.Distributed/Neolution.Extensions.Caching.Distributed.csproj b/src/Neolution.Extensions.Caching.Distributed/Neolution.Extensions.Caching.Distributed.csproj index a9a10cb..8e412e4 100644 --- a/src/Neolution.Extensions.Caching.Distributed/Neolution.Extensions.Caching.Distributed.csproj +++ b/src/Neolution.Extensions.Caching.Distributed/Neolution.Extensions.Caching.Distributed.csproj @@ -7,7 +7,7 @@ - + diff --git a/src/Neolution.Extensions.Caching.RedisHybrid/Neolution.Extensions.Caching.RedisHybrid.csproj b/src/Neolution.Extensions.Caching.RedisHybrid/Neolution.Extensions.Caching.RedisHybrid.csproj index ecdd485..d0eca69 100644 --- a/src/Neolution.Extensions.Caching.RedisHybrid/Neolution.Extensions.Caching.RedisHybrid.csproj +++ b/src/Neolution.Extensions.Caching.RedisHybrid/Neolution.Extensions.Caching.RedisHybrid.csproj @@ -8,7 +8,7 @@ - + all runtime; build; native; contentfiles; analyzers; buildtransitive From f1c979a2c48788e72bc95925d22966ecce9e9ec2 Mon Sep 17 00:00:00 2001 From: Sandro Ciervo Date: Tue, 4 Aug 2026 11:00:47 +0000 Subject: [PATCH 3/3] chore: add changeset for dependency updates Co-Authored-By: Claude Opus 5 (1M context) --- .changeset/six-toys-change.md | 14 ++++++++++++++ 1 file changed, 14 insertions(+) create mode 100644 .changeset/six-toys-change.md diff --git a/.changeset/six-toys-change.md b/.changeset/six-toys-change.md new file mode 100644 index 0000000..9e76339 --- /dev/null +++ b/.changeset/six-toys-change.md @@ -0,0 +1,14 @@ +--- +"@neolution-ch/neolution.extensions.caching.distributed": patch +"@neolution-ch/neolution.extensions.caching.redishybrid": patch +"@neolution-ch/neolution.extensions.caching.abstractions": patch +"@neolution-ch/neolution.extensions.caching.inmemory": patch +--- + +Bump MessagePack from 2.5.198 to 2.5.302 + +| Package | From | To | Bump | +| ----------- | ------- | ------- | -------- | +| MessagePack | 2.5.198 | 2.5.302 | 🟢 patch | + +Security update. MessagePack 2.5.198 is affected by 11 advisories (2 high, 9 moderate), including GHSA-hv8m-jj95-wg3x (CVE-2026-48109, CVSS 8.2) and GHSA-vh6j-jc39-fggf (CVE-2026-48506, CVSS 7.5). Both `MessagePackDistributedCache` and `MsgPackSerializer` serialize with `MessagePackCompression.Lz4BlockArray` by default, which is the mode affected by the LZ4 out-of-bounds read advisory.