Skip to content

Update dependencies to prevent exposure to transitive vulnerabilities#632

Merged
bording merged 12 commits intorelease-4.0from
GitHubSync-20241030-000546
Jan 10, 2025
Merged

Update dependencies to prevent exposure to transitive vulnerabilities#632
bording merged 12 commits intorelease-4.0from
GitHubSync-20241030-000546

Conversation

@internalautomation
Copy link
Contributor

@internalautomation internalautomation bot commented Oct 30, 2024

Symptoms

When a project has the setting NuGetAuditMode set to all, at build time there are warnings about vulnerable transitive dependencies related to this package.

Who's affected

Users are exposed if they are using previous versions of our packages, but this doesn't necessarily mean they are vulnerable.

Root cause

NuGet 6.8 released a feature called NuGetAudit and with it the possibility to scan for vulnerabilities on a project's dependency tree. That feature allowed us to detect that some of the transitive dependencies of this package had vulnerabilities, so with this patch we are making the necessary changes to resolve those warnings.

@github-actions
Copy link

This pull request has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@github-actions github-actions bot added the stale label Nov 29, 2024
@DavidBoike DavidBoike removed the stale label Dec 4, 2024
@tamararivera tamararivera force-pushed the GitHubSync-20241030-000546 branch from 1ae745e to 0543eaf Compare December 27, 2024 00:53
@tamararivera tamararivera self-assigned this Dec 27, 2024
@tamararivera tamararivera requested a review from bording December 27, 2024 01:34
@bording bording merged commit 69854a5 into release-4.0 Jan 10, 2025
3 checks passed
@bording bording deleted the GitHubSync-20241030-000546 branch January 10, 2025 22:32
@tamararivera tamararivera changed the title GitHubSync update - release-4.0 Update dependencies to prevent exposure to transitive vulnerabilities Jan 18, 2025
@tamararivera tamararivera removed their assignment Jan 21, 2025
@ngallegos ngallegos self-assigned this Jan 22, 2025
@ngallegos ngallegos added this to the 4.0.1 milestone Jan 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants