Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependencies to prevent exposure to transitive vulnerabilities #348

Merged
merged 6 commits into from
Jan 13, 2025

Conversation

internalautomation[bot]
Copy link
Contributor

@internalautomation internalautomation bot commented Oct 30, 2024

Symptoms

When a project has the setting NuGetAuditMode set to all, at build time there are warnings about vulnerable transitive dependencies related to this package.

Who's affected

Users are exposed if they are using previous versions of our packages, but this doesn't necessarily mean they are vulnerable.

Root cause

NuGet 6.8 released a feature called NuGetAudit and with it the possibility to scan for vulnerabilities on a project's dependency tree. That feature allowed us to detect that some of the transitive dependencies of this package had vulnerabilities, so with this patch we are making the necessary changes to resolve those warnings.

Copy link

This pull request has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@github-actions github-actions bot added the stale label Nov 30, 2024
@DavidBoike DavidBoike removed the stale label Dec 4, 2024
@hazel-bohon hazel-bohon mentioned this pull request Dec 6, 2024
1 task
Copy link

github-actions bot commented Jan 4, 2025

This pull request has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@bording bording force-pushed the GitHubSync-20241030-001223 branch from 3c5caac to 10b2e69 Compare January 13, 2025 21:27
@bording bording merged commit 09af3d2 into release-3.0 Jan 13, 2025
2 checks passed
@bording bording deleted the GitHubSync-20241030-001223 branch January 13, 2025 21:52
@tamararivera tamararivera added the Bug Something isn't working label Jan 18, 2025
@tamararivera tamararivera changed the title GitHubSync update - release-3.0 Update dependencies to prevent exposure to transitive vulnerabilities Jan 18, 2025
@tamararivera tamararivera added this to the 3.0.2 milestone Jan 22, 2025
@tamararivera tamararivera self-assigned this Jan 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Bug Something isn't working
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants