This release keeps dependencies and maintenance posture current for teams operating this tool.
✓ No known CVEs patched in this version
Topics
Affected surfaces
ReleasePort's take
Light signalThe release pins the SharpCompress dependency to version 0.48.0.
Why it matters: Version pinning ensures consistent builds and mitigates unexpected behavior from newer releases of SharpCompress; monitor for any breaking changes after upgrading beyond 0.48.0.
Summary
AI summaryMinor fixes and improvements.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Enable default-on server URL validation for OpenAPI plugins Enable default-on server URL validation for OpenAPI plugins Source: granite4.1:30b@2026-05-28-audit Confidence: low |
— |
| Dependency | High |
Pin SharpCompress to version 0.48.0 to fix GHSA-6c8g-7p36-r338 Pin SharpCompress to version 0.48.0 to fix GHSA-6c8g-7p36-r338 Source: granite4.1:30b@2026-05-28-audit Confidence: low |
— |
| Dependency | Low |
Pin SharpCompress to version 0.48.0 Pin SharpCompress to version 0.48.0 Source: llm_adapter@2026-05-28 Confidence: low |
— |
| Dependency | Low |
Bump .NET package version to 1.77.0 Bump .NET package version to 1.77.0 Source: granite4.1:30b@2026-05-28-audit Confidence: low |
— |
| Refactor | Medium |
Migrate Semantic Kernel to Agent Framework (AF 1.0 Compatible) Migrate Semantic Kernel to Agent Framework (AF 1.0 Compatible) Source: granite4.1:30b@2026-05-28-audit Confidence: low |
— |
Full changelog
Changes:
- 32e904c017c33eb35f7abb5a9e6e61e2e7aea81c .Net: Bump .NET package version to 1.77.0 (#14040)
- 3e180c16b3004f8b10720ea5f82c3ad136e59153 .Net: Enable default-on server URL validation for OpenAPI plugins (#14029)
- fdc6e68f5892c3f76519d22a770d7e0a12a261f6 .Net: Semantic Kernel -> Agent Framework - Migration/Samples Update (AF 1.0 Compatible) (#13852)
- 590003243af26f83cefa8a3768688065a8b5484e .Net: Pin SharpCompress 0.48.0 to fix GHSA-6c8g-7p36-r338 (#13977)
This list of changes was auto generated.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About semantic-kernel
Integrate cutting-edge LLM technology quickly and easily into your apps
Related context
Related tools
Earlier breaking changes
- vpython-1.43.0 Updates OpenAPI document parsing options in Python.
Beta — feedback welcome: [email protected]