From dc9abf674bc9e38521171a6bfc1cb04af73c15c3 Mon Sep 17 00:00:00 2001 From: Joseph Doherty Date: Fri, 12 Jun 2026 08:04:04 -0400 Subject: [PATCH] fix(deps): bump MessagePack 2.5.187 -> 2.5.301 (CVE-2026-48109 / GHSA-hv8m-jj95-wg3x) LZ4-decompression out-of-bounds read in MessagePack < 2.5.301 (transitive via the Historian.Wonderware driver). 2.5.301 is the patched v2-series release; stays on v2 (no v3 major bump). Restore no longer fails NU1903. --- Directory.Packages.props | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Directory.Packages.props b/Directory.Packages.props index e77aacd6..af16d353 100644 --- a/Directory.Packages.props +++ b/Directory.Packages.props @@ -32,7 +32,7 @@ - +