Skip to content

Fixed transitive npgsql vulnerabilities in npgsql < v8.0.3#526

Merged
1nf0rmagician merged 1 commit intodevfrom
fix/npgsql-dependency
Feb 24, 2025
Merged

Fixed transitive npgsql vulnerabilities in npgsql < v8.0.3#526
1nf0rmagician merged 1 commit intodevfrom
fix/npgsql-dependency

Conversation

@dbeuchler
Copy link
Member

@dbeuchler dbeuchler commented Feb 24, 2025

The npgsql dependency does have open vulnerabilities

Affecting npgsql package, versions [,4.0.14)[4.1.0,4.1.13)[5.0.0,5.0.18)[6.0.0-preview2,6.0.11)[7.0.0-preview.1,7.0.7)[8.0.0-preview.1,8.0.3)

Source: https://security.snyk.io/vuln/SNYK-DOTNET-NPGSQL-6825563

I updated the minimum efCore version to 8.0.4 to fix this issue.

Sorry for the amount of changes in the file but someone has destroyed the intendation. (Tabs instead of spaces)

@dbeuchler dbeuchler requested review from 1nf0rmagician and seveneleven and removed request for seveneleven February 24, 2025 13:27
Copy link
Member

@1nf0rmagician 1nf0rmagician left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We are currently in the process of adding .editorconfig files to all repositories to prevent these formatting issues in the future 👍

@1nf0rmagician 1nf0rmagician merged commit 7d29bb0 into dev Feb 24, 2025
8 checks passed
@1nf0rmagician 1nf0rmagician deleted the fix/npgsql-dependency branch February 24, 2025 15:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants