Skip to content

Commit 582e00a

Browse files
authored
Merge pull request #1806 from microsoft/security/transitive-deps
fix: directly adds non-vulnerable versions of transitive deps to resolve alerts
2 parents e7062d6 + b67e0d7 commit 582e00a

File tree

3 files changed

+8
-0
lines changed

3 files changed

+8
-0
lines changed

src/Microsoft.OpenApi.Hidi/Microsoft.OpenApi.Hidi.csproj

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,10 @@
3939
<PackageReference Include="Microsoft.OpenApi.OData" Version="2.0.0-preview.2" />
4040
<PackageReference Include="Microsoft.OpenApi.ApiManifest" Version="0.5.0-preview" />
4141
<PackageReference Include="System.CommandLine.Hosting" Version="0.4.0-alpha.22272.1" />
42+
<!--STJ
43+
required until Microsoft.Extensions.Logging.Console and Microsoft.Extensions.Configuration.Json
44+
update their dependencies -->
45+
<PackageReference Include="System.Text.Json" Version="8.0.4" />
4246
</ItemGroup>
4347

4448
<ItemGroup>

src/Microsoft.OpenApi.Workbench/Microsoft.OpenApi.Workbench.csproj

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,8 @@
1010
<ItemGroup>
1111
<PackageReference Include="Microsoft.VisualStudio.Threading" Version="17.11.20" />
1212
<PackageReference Include="Microsoft.Windows.Compatibility" Version="8.0.8" />
13+
<!-- Microsoft.Windows.Compatibility 8.0.8 depends on 8.0.0 this dependency can be removed once they update theirs -->
14+
<PackageReference Include="System.Formats.Asn1" Version="8.0.1" />
1315
</ItemGroup>
1416
<ItemGroup>
1517
<Resource Include="Themes\Metro\HowToApplyTheme.txt" />

test/Microsoft.OpenApi.Readers.Tests/Microsoft.OpenApi.Readers.Tests.csproj

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,8 @@
2323
<PackageReference Include="SharpYaml" Version="2.1.1" />
2424
<PackageReference Include="xunit" Version="2.9.0" />
2525
<PackageReference Include="xunit.runner.visualstudio" Version="2.8.2" PrivateAssets="all" />
26+
<!--STJ required until Microsoft.Extensions.Logging.Console and Microsoft.Extensions.Configuration.Json update their dependencies -->
27+
<PackageReference Include="System.Text.Json" Version="8.0.4" />
2628
</ItemGroup>
2729

2830
<ItemGroup>

0 commit comments

Comments
 (0)