Bump transitive Microsoft.Bcl.Memory#345
Conversation
There was a problem hiding this comment.
Pull request overview
Pins a patched Microsoft.Bcl.Memory version in the skill-validator tool to mitigate a vulnerability introduced via the transitive dependency chain from Microsoft.ML.Tokenizers.Data.Cl100kBase.
Changes:
- Add an explicit
PackageReferencetoMicrosoft.Bcl.Memory9.0.14inSkillValidator.csprojto override the vulnerable transitive version.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
You can also share your feedback on Copilot code review. Take the survey.
Skill Validation Results
[1] Quality unchanged but weighted score is -25.2% due to: judgment, tokens (11838 → 54653), quality, tool calls (0 → 3), time (17.0s → 45.4s)
Model: claude-opus-4.6 | Judge: claude-opus-4.6 |
Motivation
Microsoft.ML.Tokenizers.Data.Cl100kBase2.0.0 transitively depends onMicrosoft.Bcl.Memory9.0.4, which has a vulnerabilityThere is not a newer stable version - so pinning M.B.M