Skip to content

Commit 076223b

Browse files
author
Simeon
authored
Fix for security issue in System.Text.Encodings.Web v4.7.1. (#434)
Error reported: Microsoft.Toolkit.Uwp.UI.Lottie v7 uses System.Text.Encodings.Web v4.7.1 which has a high severity security vulnerability and as such doesn't pass component governance This upgrades all of the runtime NuGet packages to the latest version.
1 parent 42a35f0 commit 076223b

File tree

9 files changed

+17
-17
lines changed

9 files changed

+17
-17
lines changed

Lottie-Windows/Lottie-Windows.csproj

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -29,16 +29,16 @@
2929

3030
<ItemGroup>
3131
<PackageReference Include="Microsoft.UI.Xaml">
32-
<Version>2.4.2</Version>
32+
<Version>2.5.0</Version>
3333
<Generator>MSBuild:Compile</Generator>
3434
<SubType>Designer</SubType>
3535
</PackageReference>
3636
<PackageReference Include="System.Memory" Version="4.5.4" />
3737
<PackageReference Include="System.Numerics.Vectors">
3838
<Version>4.5.0</Version>
3939
</PackageReference>
40-
<PackageReference Include="System.Runtime.CompilerServices.Unsafe" Version="4.7.1" />
41-
<PackageReference Include="System.Text.Json" Version="4.7.2" />
40+
<PackageReference Include="System.Runtime.CompilerServices.Unsafe" Version="5.0.0" />
41+
<PackageReference Include="System.Text.Json" Version="5.0.1" />
4242
<PackageReference Include="System.ValueTuple">
4343
<Version>4.5.0</Version>
4444
</PackageReference>

LottieGen/MSBuildTask/LottieGen.MsBuild.csproj

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,15 +21,15 @@
2121
</PropertyGroup>
2222

2323
<ItemGroup>
24-
<PackageReference Include="Microsoft.Build.Utilities.Core" Version="16.8.0" />
24+
<PackageReference Include="Microsoft.Build.Utilities.Core" Version="16.9.0" />
2525
</ItemGroup>
2626

2727
<!--
2828
Ensure the LottieGen.exe single-file app with no dependencies has
2929
been built and published so we can copy its outputs.
3030
-->
3131
<Target Name="EnsureLottieGenExeIsBuilt">
32-
<MSBuild Projects="..\win-x64\LottieGen.win-x64.csproj" Targets="Publish"/>
32+
<MSBuild Projects="..\win-x64\LottieGen.win-x64.csproj" Targets="Publish" />
3333
</Target>
3434

3535
<!-- Generates the .nuspec file. -->

LottieViewer/LottieViewer.csproj

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -212,19 +212,19 @@
212212
</ItemGroup>
213213
<ItemGroup>
214214
<PackageReference Include="Microsoft.NETCore.UniversalWindowsPlatform">
215-
<Version>6.2.10</Version>
215+
<Version>6.2.12</Version>
216216
</PackageReference>
217217
<PackageReference Include="Microsoft.UI.Xaml">
218-
<Version>2.4.2</Version>
218+
<Version>2.5.0</Version>
219219
</PackageReference>
220220
<PackageReference Include="System.Memory">
221221
<Version>4.5.4</Version>
222222
</PackageReference>
223223
<PackageReference Include="System.Runtime.CompilerServices.Unsafe">
224-
<Version>4.7.1</Version>
224+
<Version>5.0.0</Version>
225225
</PackageReference>
226226
<PackageReference Include="System.Text.Json">
227-
<Version>4.7.2</Version>
227+
<Version>5.0.1</Version>
228228
</PackageReference>
229229
<PackageReference Include="Win2D.uwp">
230230
<Version>1.25.0</Version>

dlls/GenericData/GenericData.dll.csproj

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@
1111

1212
<ItemGroup>
1313
<PackageReference Include="System.Memory" Version="4.5.4" />
14-
<PackageReference Include="System.Runtime.CompilerServices.Unsafe" Version="4.7.1" />
14+
<PackageReference Include="System.Runtime.CompilerServices.Unsafe" Version="5.0.0" />
1515
</ItemGroup>
1616

1717
</Project>

dlls/LottieData/LottieData.dll.csproj

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@
1111

1212
<ItemGroup>
1313
<PackageReference Include="System.Memory" Version="4.5.4" />
14-
<PackageReference Include="System.Runtime.CompilerServices.Unsafe" Version="4.7.1" />
14+
<PackageReference Include="System.Runtime.CompilerServices.Unsafe" Version="5.0.0" />
1515
</ItemGroup>
1616

1717
<ItemGroup>

dlls/LottieMetadata/LottieMetadata.dll.csproj

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@
1111

1212
<ItemGroup>
1313
<PackageReference Include="System.Memory" Version="4.5.4" />
14-
<PackageReference Include="System.Runtime.CompilerServices.Unsafe" Version="4.7.1" />
14+
<PackageReference Include="System.Runtime.CompilerServices.Unsafe" Version="5.0.0" />
1515
</ItemGroup>
1616

1717
</Project>

dlls/LottieReader/LottieReader.dll.csproj

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@
1010
<Import Project="..\..\source\LottieReader\LottieReader.projitems" Label="Shared" />
1111

1212
<ItemGroup>
13-
<PackageReference Include="System.Text.Json" Version="4.7.2" />
13+
<PackageReference Include="System.Text.Json" Version="5.0.1" />
1414
</ItemGroup>
1515

1616
<ItemGroup>

samples/LottieSamples/LottieSamples.csproj

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -259,13 +259,13 @@
259259
</ItemGroup>
260260
<ItemGroup>
261261
<PackageReference Include="Microsoft.NETCore.UniversalWindowsPlatform">
262-
<Version>6.2.10</Version>
262+
<Version>6.2.12</Version>
263263
</PackageReference>
264264
<PackageReference Include="Microsoft.Toolkit.Uwp.UI.Lottie">
265-
<Version>6.1.0</Version>
265+
<Version>7.0.0</Version>
266266
</PackageReference>
267267
<PackageReference Include="Microsoft.UI.Xaml">
268-
<Version>2.4.2</Version>
268+
<Version>2.5.0</Version>
269269
</PackageReference>
270270
</ItemGroup>
271271
<ItemGroup>

version.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
2-
"version": "7.0.0-build.{height}",
2+
"version": "7.0.1-build.{height}",
33
"publicReleaseRefSpec": [
44
"^refs/heads/master$", // we release out of master
55
"^refs/heads/dev$", // we release out of dev

0 commit comments

Comments
 (0)