From 86d48ff8a5d4e37dc6e7a4d0f91293b02c568841 Mon Sep 17 00:00:00 2001 From: Joseph Doherty Date: Sat, 18 Jul 2026 05:22:10 -0400 Subject: [PATCH] chore(secrets): bump ZB.MOM.WW.Secrets 0.1.2 -> 0.2.0 Version hygiene + picks up the G-8 KEK-rotation surface, and is the precondition for adopting clustered secret replication. NOT a security fix for this repo, despite what the original message said. A/B against the 0.1.2 baseline shows SQLitePCLRaw.lib.e_sqlite3 already resolved 2.1.12, supplied transitively by ZB.MOM.WW.Auth.ApiKeys 0.1.5 (commit 50d79ed1). Note: Directory.Packages.props suppresses GHSA-2m69-gcr7-jv3q and its comment asserts 'the only patched native lib is the SQLitePCLRaw 3.x line'. That appears incorrect for this advisory - 2.1.12 patches it. Settle before removing the suppression; HistorianGateway's separate 3.50.3 pin cites a DIFFERENT CVE (CVE-2025-6965), which may be the source of the confusion. --- Directory.Packages.props | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/Directory.Packages.props b/Directory.Packages.props index 75f68348..7d52e0b7 100644 --- a/Directory.Packages.props +++ b/Directory.Packages.props @@ -86,9 +86,9 @@ - - - + + +