Skip to content

Commit a21a307

Browse files
authored
[repo] Enable NugetAudit - part 1 (open-telemetry#2034)
1 parent 43a0aeb commit a21a307

File tree

10 files changed

+20
-10
lines changed

10 files changed

+20
-10
lines changed

build/Common.nonprod.props

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@
2222
-->
2323
<BenchmarkDotNetPkgVer>[0.13.12,0.14)</BenchmarkDotNetPkgVer>
2424
<MicrosoftExtensionsHostingPkgVer>8.0.0</MicrosoftExtensionsHostingPkgVer>
25-
<MicrosoftNETTestSdkPkgVer>[17.11.0,18.0)</MicrosoftNETTestSdkPkgVer>
25+
<MicrosoftNETTestSdkPkgVer>[17.11.1,18.0)</MicrosoftNETTestSdkPkgVer>
2626
<OpenTelemetryExporterInMemoryPkgVer>$(OpenTelemetryCoreLatestVersion)</OpenTelemetryExporterInMemoryPkgVer>
2727
<OpenTelemetryExporterInMemoryLatestPreReleasePkgVer>$(OpenTelemetryCoreLatestPrereleaseVersion)</OpenTelemetryExporterInMemoryLatestPreReleasePkgVer>
2828
<SupportedNetTargets>net8.0;net6.0</SupportedNetTargets>

build/Common.props

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,10 @@
1313
<AnalysisLevel>latest-all</AnalysisLevel>
1414
<Nullable>enable</Nullable>
1515
<ImplicitUsings>enable</ImplicitUsings>
16+
<NuGetAudit>true</NuGetAudit>
17+
<!-- NuGetAuditMode will be uncommented in the future PR when all issues will be fixed. -->
18+
<!--<NuGetAuditMode>all</NuGetAuditMode>-->
19+
<NuGetAuditLevel>low</NuGetAuditLevel>
1620
</PropertyGroup>
1721

1822
<PropertyGroup Condition="'$(Configuration)'=='Debug'">
@@ -45,7 +49,7 @@
4549
<StackExchangeRedisPkgVer>[2.6.122,3.0)</StackExchangeRedisPkgVer>
4650
<ConfluentKafkaPkgVer>[2.4.0,3.0)</ConfluentKafkaPkgVer>
4751
<CassandraCSharpDriverPkgVer>[3.16.0,4.0)</CassandraCSharpDriverPkgVer>
48-
<StyleCopAnalyzersPkgVer>[1.2.0-beta.507,2.0)</StyleCopAnalyzersPkgVer>
52+
<StyleCopAnalyzersPkgVer>[1.2.0-beta.556,2.0)</StyleCopAnalyzersPkgVer>
4953
<SystemNetHttp>[4.3.4,)</SystemNetHttp>
5054
<SystemReflectionEmitLightweightPkgVer>4.7.0</SystemReflectionEmitLightweightPkgVer>
5155
<SystemTextJsonPkgVer>[6.0.0,)</SystemTextJsonPkgVer>

examples/kafka/Examples.ConfluentKafka.csproj

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,5 +11,7 @@
1111
<PackageReference Include="OpenTelemetry.Extensions.Hosting" Version="$(OpenTelemetryCoreLatestVersion)" />
1212
<PackageReference Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" Version="$(OpenTelemetryCoreLatestVersion)" />
1313
<PackageReference Include="OpenTelemetry.Exporter.Console" Version="$(OpenTelemetryCoreLatestVersion)" />
14+
<!-- System.Text.Json is indirect reference. It is needed to upgrade it directly to avoid https://github.com/advisories/GHSA-hh2w-p6rv-4g7w -->
15+
<PackageReference Include="System.Text.Json" Version="8.0.4" />
1416
</ItemGroup>
1517
</Project>

examples/owin/Examples.Owin.csproj

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
</PropertyGroup>
77

88
<ItemGroup>
9-
<PackageReference Include="Microsoft.AspNet.WebApi.OwinSelfHost" Version="5.2.9" />
9+
<PackageReference Include="Microsoft.AspNet.WebApi.OwinSelfHost" Version="5.3.0" />
1010
<PackageReference Include="OpenTelemetry.Exporter.Console" Version="$(OpenTelemetryCoreLatestVersion)" />
1111
</ItemGroup>
1212

test/OpenTelemetry.Instrumentation.ConfluentKafka.Tests/OpenTelemetry.Instrumentation.ConfluentKafka.Tests.csproj

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,8 @@
2222
<PackageReference Include="OpenTelemetry.Exporter.InMemory" Version="$(OpenTelemetryExporterInMemoryPkgVer)" />
2323
<PackageReference Include="Microsoft.Extensions.Hosting" Version="$(MicrosoftExtensionsOptionsPkgVer)" />
2424
<PackageReference Condition="$(TargetFramework) == 'net462'" Include="Confluent.Kafka" Version="$(ConfluentKafkaPkgVer)" />
25+
<!-- System.Text.Json is indirect reference. It is needed to upgrade it directly to avoid https://github.com/advisories/GHSA-hh2w-p6rv-4g7w -->
26+
<PackageReference Include="System.Text.Json" Version="8.0.4" />
2527
</ItemGroup>
2628

2729
</Project>

test/OpenTelemetry.Instrumentation.EntityFrameworkCore.Tests/OpenTelemetry.Instrumentation.EntityFrameworkCore.Tests.csproj

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,11 +6,11 @@
66
</PropertyGroup>
77

88
<ItemGroup Condition=" '$(TargetFramework)' == 'net8.0' ">
9-
<PackageReference Include="Microsoft.EntityFrameworkCore.Sqlite" Version="8.0.0" />
9+
<PackageReference Include="Microsoft.EntityFrameworkCore.Sqlite" Version="8.0.8" />
1010
</ItemGroup>
1111

1212
<ItemGroup Condition=" '$(TargetFramework)' == 'net6.0' ">
13-
<PackageReference Include="Microsoft.EntityFrameworkCore.Sqlite" Version="6.0.25" />
13+
<PackageReference Include="Microsoft.EntityFrameworkCore.Sqlite" Version="6.0.33" />
1414
</ItemGroup>
1515

1616
<ItemGroup>

test/OpenTelemetry.Instrumentation.Owin.Tests/OpenTelemetry.Instrumentation.Owin.Tests.csproj

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
</PropertyGroup>
77

88
<ItemGroup>
9-
<PackageReference Include="Microsoft.AspNet.WebApi.OwinSelfHost" Version="5.2.7" />
9+
<PackageReference Include="Microsoft.AspNet.WebApi.OwinSelfHost" Version="5.3.0" />
1010
<PackageReference Include="OpenTelemetry.Exporter.InMemory" Version="$(OpenTelemetryExporterInMemoryPkgVer)" />
1111
</ItemGroup>
1212

test/OpenTelemetry.Instrumentation.Quartz.Tests/OpenTelemetry.Instrumentation.Quartz.Tests.csproj

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99
<ItemGroup>
1010
<PackageReference Include="OpenTelemetry" Version="$(OpenTelemetryCoreLatestVersion)" />
1111
<PackageReference Include="OpenTelemetry.Exporter.InMemory" Version="$(OpenTelemetryExporterInMemoryPkgVer)" />
12-
<PackageReference Include="Quartz" Version="3.3.2" />
12+
<PackageReference Include="Quartz" Version="3.6.3" />
1313
</ItemGroup>
1414

1515
<ItemGroup>

test/OpenTelemetry.Instrumentation.SqlClient.Tests/OpenTelemetry.Instrumentation.SqlClient.Tests.csproj

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -15,9 +15,9 @@
1515
</ItemGroup>
1616

1717
<ItemGroup>
18-
<PackageReference Include="Microsoft.Data.SqlClient" Version="5.1.3" />
19-
<PackageReference Include="Testcontainers.MsSql" Version="3.9.0" />
20-
<PackageReference Include="Testcontainers.SqlEdge" Version="3.9.0" />
18+
<PackageReference Include="Microsoft.Data.SqlClient" Version="5.2.2" />
19+
<PackageReference Include="Testcontainers.MsSql" Version="3.10.0" />
20+
<PackageReference Include="Testcontainers.SqlEdge" Version="3.10.0" />
2121
<PackageReference Include="OpenTelemetry.Exporter.InMemory" Version="$(OpenTelemetryExporterInMemoryPkgVer)" />
2222
</ItemGroup>
2323

test/OpenTelemetry.Instrumentation.StackExchangeRedis.Tests/OpenTelemetry.Instrumentation.StackExchangeRedis.Tests.csproj

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,5 +21,7 @@
2121
<PackageReference Include="OpenTelemetry.Extensions.Hosting" Version="$(OpenTelemetryCoreLatestVersion)" />
2222
<PackageReference Include="OpenTelemetry.Exporter.InMemory" Version="$(OpenTelemetryExporterInMemoryPkgVer)" />
2323
<PackageReference Include="Microsoft.Extensions.Hosting" Version="$(MicrosoftExtensionsHostingPkgVer)" />
24+
<!-- System.Text.Json is indirect reference. It is needed to upgrade it directly to avoid https://github.com/advisories/GHSA-hh2w-p6rv-4g7w -->
25+
<PackageReference Include="System.Text.Json" Version="8.0.4" />
2426
</ItemGroup>
2527
</Project>

0 commit comments

Comments
 (0)