Skip to content

Update dependency System.Data.SqlClient to 4.8.6 [SECURITY]#268

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/nuget-system.data.sqlclient-vulnerability
Open

Update dependency System.Data.SqlClient to 4.8.6 [SECURITY]#268
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/nuget-system.data.sqlclient-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 8, 2026

This PR contains the following updates:

Package Change Age Confidence
System.Data.SqlClient 4.8.54.8.6 age confidence

Microsoft.Data.SqlClient and System.Data.SqlClient vulnerable to SQL Data Provider Security Feature Bypass

CVE-2024-0056 / GHSA-98g6-xh36-x2p7

More information

Details

Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot force-pushed the renovate/nuget-system.data.sqlclient-vulnerability branch from e154eec to b97223a Compare April 21, 2026 20:01
@renovate renovate Bot changed the title Update dependency System.Data.SqlClient to 4.8.6 [SECURITY] Update dependency System.Data.SqlClient to 4.8.6 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot deleted the renovate/nuget-system.data.sqlclient-vulnerability branch April 27, 2026 19:16
@renovate renovate Bot changed the title Update dependency System.Data.SqlClient to 4.8.6 [SECURITY] - autoclosed Update dependency System.Data.SqlClient to 4.8.6 [SECURITY] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate renovate Bot force-pushed the renovate/nuget-system.data.sqlclient-vulnerability branch 2 times, most recently from b97223a to d87eaf3 Compare April 27, 2026 21:35
@Ahoo-Wang Ahoo-Wang added the dependencies Pull requests that update a dependency file label May 14, 2026
@renovate renovate Bot force-pushed the renovate/nuget-system.data.sqlclient-vulnerability branch from d87eaf3 to e3ae969 Compare May 14, 2026 05:20
@codecov
Copy link
Copy Markdown

codecov Bot commented May 14, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 72.75%. Comparing base (00d4df2) to head (0f355e6).
⚠️ Report is 1 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master     #268      +/-   ##
==========================================
+ Coverage   72.74%   72.75%   +0.01%     
==========================================
  Files         314      314              
  Lines        7180     7180              
  Branches     1007     1007              
==========================================
+ Hits         5223     5224       +1     
+ Misses       1726     1723       -3     
- Partials      231      233       +2     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@renovate renovate Bot force-pushed the renovate/nuget-system.data.sqlclient-vulnerability branch from e3ae969 to 0f355e6 Compare May 14, 2026 10:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant