Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

System.Text.Json.7.0.3 - Outdated - Vulnerable #90

Open
guyulmaz opened this issue Aug 27, 2024 · 1 comment
Open

System.Text.Json.7.0.3 - Outdated - Vulnerable #90

guyulmaz opened this issue Aug 27, 2024 · 1 comment

Comments

@guyulmaz
Copy link

I'm submitting a...

Current behavior

System.Text.Json.7.0.3 - Outdated - Vulnerable: [ Severity: 2, https://github.com/advisories/GHSA-hh2w-p6rv-4g7w ]
Uno.UITest.Selenium.1.1.0-dev.70
Uno.UITest.Helpers.1.1.0-dev.70

Expected behavior

pump up System.Text.Json version

Minimal reproduction of the problem with instructions

I'm using nugetmonitor extention at vs 2022, it is giving hifgliting this vulnerability warning.

Environment

Package Version(s): 

Visual Studio
- [ x] 2022 (version: )
- [ ] 2019 Preview (version: )
- [ ] for Mac (version: )
@jeromelaban
Copy link
Member

Thanks for the report. Dealing with transitive vulnerabilities is a hot topic lately, particularly with net9, and the policy for now is to not update the dependencies for libraries unless there's a binary breaking change, as the apps can do it explicitly. We're expecting changes with NuGet/Home#7344 (comment).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants