Skip to content

Commit 378a1a3

Browse files
authored
[repo] Enable NugetAudit - finalize (open-telemetry#2079)
1 parent 18c5a26 commit 378a1a3

File tree

9 files changed

+31
-6
lines changed

9 files changed

+31
-6
lines changed

build/Common.nonprod.props

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@
2828
<SupportedNetTargets>net8.0;net6.0</SupportedNetTargets>
2929
<XUnitRunnerVisualStudioPkgVer>[2.8.2,3.0)</XUnitRunnerVisualStudioPkgVer>
3030
<XUnitPkgVer>[2.9.0,3.0)</XUnitPkgVer>
31-
<WiremockNetPkgVer>[1.6.1,2.0)</WiremockNetPkgVer>
31+
<WiremockNetPkgVer>[1.6.3,2.0)</WiremockNetPkgVer>
3232
</PropertyGroup>
3333

3434
<ItemGroup Condition="'$(IsTestProject)' == 'true'">

build/Common.props

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,8 +14,7 @@
1414
<Nullable>enable</Nullable>
1515
<ImplicitUsings>enable</ImplicitUsings>
1616
<NuGetAudit>true</NuGetAudit>
17-
<!-- NuGetAuditMode will be uncommented in the future PR when all issues will be fixed. -->
18-
<!--<NuGetAuditMode>all</NuGetAuditMode>-->
17+
<NuGetAuditMode>all</NuGetAuditMode>
1918
<NuGetAuditLevel>low</NuGetAuditLevel>
2019
</PropertyGroup>
2120

examples/wcf/client-core/Examples.Wcf.Client.DotNet.csproj

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,8 +9,10 @@
99
<PackageReference Include="System.ServiceModel.Http" Version="4.7.0" />
1010
<PackageReference Include="System.ServiceModel.NetTcp" Version="4.7.0" />
1111
<PackageReference Include="Microsoft.Extensions.Configuration.Json" Version="8.0.0" />
12-
<PackageReference Include="Microsoft.Extensions.Configuration.Binder" Version="8.0.0" />
12+
<PackageReference Include="Microsoft.Extensions.Configuration.Binder" Version="8.0.2" />
1313
<PackageReference Include="OpenTelemetry.Exporter.Zipkin" Version="$(OpenTelemetryCoreLatestVersion)" />
14+
<!-- System.Text.Json is indirect reference. It is needed to upgrade it directly to avoid https://github.com/advisories/GHSA-hh2w-p6rv-4g7w -->
15+
<PackageReference Include="System.Text.Json" Version="8.0.4" />
1416
</ItemGroup>
1517

1618
<ItemGroup>

examples/wcf/shared/Examples.Wcf.Shared.csproj

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,16 +2,23 @@
22

33
<PropertyGroup>
44
<!-- OmniSharp/VS Code requires TargetFrameworks to be in descending order for IntelliSense and analysis. -->
5-
<TargetFrameworks>netstandard2.0;net462</TargetFrameworks>
5+
<TargetFrameworks>net8.0;net462</TargetFrameworks>
66
</PropertyGroup>
77

88
<ItemGroup Condition="'$(TargetFramework)' == 'net462'">
99
<Reference Include="System.ServiceModel" />
1010
<Reference Include="System.ServiceModel.Web" />
1111
</ItemGroup>
1212

13-
<ItemGroup Condition="'$(TargetFramework)' == 'netstandard2.0'">
13+
<ItemGroup Condition="'$(TargetFramework)' == 'net8.0'">
1414
<PackageReference Include="System.ServiceModel.Primitives" Version="4.7.0" />
1515
</ItemGroup>
1616

17+
<ItemGroup>
18+
<!-- System.Security.Cryptography.Xml is indirect reference. It is needed to upgrade it directly to avoid https://github.com/advisories/GHSA-rxg9-xrhp-64gj -->
19+
<PackageReference Include="System.Security.Cryptography.Xml" Version="4.7.1" />
20+
<!-- System.Drawing.Common is indirect reference. It is needed to upgrade it directly to avoid https://github.com/advisories/GHSA-rxg9-xrhp-64gj -->
21+
<PackageReference Include="System.Drawing.Common" Version="4.7.3" />
22+
</ItemGroup>
23+
1724
</Project>

test/OpenTelemetry.AotCompatibility.TestApp/OpenTelemetry.AotCompatibility.TestApp.csproj

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,11 @@
1313
<Compile Include="$(RepoRoot)\src\Shared\PropertyFetcher.AOT.cs" Link="Includes\PropertyFetcher.AOT.cs" />
1414
</ItemGroup>
1515

16+
<ItemGroup>
17+
<!-- System.Private.Uri is indirect reference. It is needed to upgrade it directly to avoid https://github.com/advisories/GHSA-5f2m-466j-3848 -->
18+
<PackageReference Include="System.Private.Uri" Version="4.3.2" />
19+
</ItemGroup>
20+
1621
<ItemGroup>
1722
<!--
1823
When adding projects here please also update the verify-aot-compat job in

test/OpenTelemetry.Exporter.Geneva.Tests/OpenTelemetry.Exporter.Geneva.Tests.csproj

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,10 @@
2121
<PackageReference Include="StrongNamer" Version="0.2.5" />
2222
<PackageReference Include="OpenTelemetry.Exporter.InMemory" Version="$(OpenTelemetryExporterInMemoryLatestPreReleasePkgVer)" />
2323
<PackageReference Include="OpenTelemetry.Extensions.Hosting" Version="$(OTelSdkVersion)" />
24+
<!-- System.Text.RegularExpressions is indirect reference. It is needed to upgrade it directly to avoid https://github.com/advisories/GHSA-cmhx-cq75-c4mj -->
25+
<PackageReference Include="System.Text.RegularExpressions" Version="4.3.1" />
26+
<!-- System.Net.Http is indirect reference. It is needed to upgrade it directly to avoid https://github.com/advisories/GHSA-7jgj-8wvc-jh57 -->
27+
<PackageReference Include="System.Net.Http" Version="4.3.4" />
2428
</ItemGroup>
2529

2630
<ItemGroup>

test/OpenTelemetry.Extensions.Enrichment.Tests/OpenTelemetry.Extensions.Enrichment.Tests.csproj

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@
1111
<PackageReference Include="Microsoft.Extensions.Hosting" Version="$(MicrosoftExtensionsHostingPkgVer)" />
1212
<PackageReference Include="OpenTelemetry.Extensions.Hosting" Version="$(OpenTelemetryCoreLatestVersion)" />
1313
<PackageReference Include="OpenTelemetry.Exporter.InMemory" Version="$(OpenTelemetryCoreLatestVersion)" />
14+
<!-- System.Text.Json is indirect reference. It is needed to upgrade it directly to avoid https://github.com/advisories/GHSA-hh2w-p6rv-4g7w -->
15+
<PackageReference Include="System.Text.Json" Version="8.0.4" />
16+
<!-- System.Drawing.Common is indirect reference. It is needed to upgrade it directly to avoid https://github.com/advisories/GHSA-rxg9-xrhp-64gj -->
17+
<PackageReference Include="System.Drawing.Common" Version="4.7.3" />
1418
</ItemGroup>
1519

1620
<ItemGroup>

test/OpenTelemetry.Instrumentation.Wcf.Tests/OpenTelemetry.Instrumentation.Wcf.Tests.csproj

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,8 @@
2222
<ItemGroup Condition="'$(TargetFramework)' != 'net462'">
2323
<PackageReference Include="System.ServiceModel.Http" Version="4.7.0" />
2424
<PackageReference Include="System.ServiceModel.NetTcp" Version="4.7.0" />
25+
<!-- System.Drawing.Common is indirect reference. It is needed to upgrade it directly to avoid https://github.com/advisories/GHSA-rxg9-xrhp-64gj -->
26+
<PackageReference Include="System.Drawing.Common" Version="4.7.3" />
2527
</ItemGroup>
2628

2729
<ItemGroup>

test/OpenTelemetry.Sampler.AWS.Tests/OpenTelemetry.Sampler.AWS.Tests.csproj

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,8 @@
77

88
<ItemGroup>
99
<PackageReference Include="Wiremock.Net" Version="$(WiremockNetPkgVer)" />
10+
<!-- System.Text.RegularExpressions is indirect reference. It is needed to upgrade it directly to avoid https://github.com/advisories/GHSA-cmhx-cq75-c4mj -->
11+
<PackageReference Include="System.Text.RegularExpressions" Version="4.3.1" />
1012
</ItemGroup>
1113

1214
<ItemGroup>

0 commit comments

Comments
 (0)