Skip to content

Commit 0897d81

Browse files
committed
chore: Update CloudNative.CloudEvents.Avro dependencies
- Updated to Apache.Avro 1.11.1 on general principle - Added explicit dependency on Newtonsoft.Json 13.0.1 to avoid taking a transitive dependency on a vulnerable version Addresses short-term concerns of #245. Signed-off-by: Jon Skeet <[email protected]>
1 parent b2f4c7b commit 0897d81

File tree

1 file changed

+7
-1
lines changed

1 file changed

+7
-1
lines changed

src/CloudNative.CloudEvents.Avro/CloudNative.CloudEvents.Avro.csproj

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,13 @@
99
</PropertyGroup>
1010

1111
<ItemGroup>
12-
<PackageReference Include="Apache.Avro" Version="1.11.0" />
12+
<PackageReference Include="Apache.Avro" Version="1.11.1" />
13+
<!--
14+
- Explicit dependency just to avoid a vulnerable version being exposed via Apache.Avro.
15+
- If Apache.Avro publishes a new version that updates the dependency (to 13.0.1 or higher)
16+
- we can remove our explicit dependency.
17+
-->
18+
<PackageReference Include="Newtonsoft.Json" Version="13.0.1" />
1319
<ProjectReference Include="..\CloudNative.CloudEvents\CloudNative.CloudEvents.csproj" />
1420
</ItemGroup>
1521

0 commit comments

Comments
 (0)