Update microsoft_gsl from v4.0.0 to v4.2.1 (fixes C4875 deprecation) (#28527)
### Description
Upgrades `microsoft_gsl` to v4.2.1 and patches `GSL_SUPPRESS` to
stringify its argument for MSVC, fixing the C4875 deprecation warning in
VC++ 18.6.0.
- **`cmake/deps.txt`** — Bump to v4.2.1
- **`cmake/patches/gsl/1064.patch`** — Removed; the NVCC guard
(`!defined(__NVCC__)`) is already upstream in v4.2.1
- **`cmake/patches/gsl/1213.patch`** — New patch: `[[gsl::suppress(x)]]`
→ `[[gsl::suppress(#x)]]` for MSVC, matching upstream
microsoft/GSL@543d0dd (PR microsoft/GSL#1213)
- **`cmake/external/onnxruntime_external_deps.cmake`** — Removed the
`if(onnxruntime_USE_CUDA)` conditional around the patch; the stringify
fix applies to all MSVC builds, not just CUDA
- **`cmake/vcpkg.json`** — Added `"version>=": "4.2.1"` constraint for
`ms-gsl` to ensure vcpkg builds also pick up a version that includes the
NVCC guard fix
### Motivation and Context
GSL v4.0.0's `GSL_SUPPRESS` macro passes a non-string-literal to
`[[gsl::suppress()]]`. VC++ 18.6.0 deprecates this form (C4875), and a
future MSVC release will remove it entirely, breaking the build. The
warning fires on essentially every translation unit via `capture.h` /
`narrow.h`.
The upstream fix (stringify via `#x`) hasn't shipped in a GSL release
yet, so a local patch is still needed until a future GSL release
includes it.
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: tianleiwu <30328909+tianleiwu@users.noreply.github.com>
Co-authored-by: Tianlei Wu <tlwu@microsoft.com>