-
Notifications
You must be signed in to change notification settings - Fork 139
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
NuGet dependency vulnerabilities #146
Comments
there is also azure core identity that is referenced for no reasons.. REMOVE THIS ASAP.. |
Follow this as well - can we get a fix in for this? |
For those running into this, I fixed this by adding the dependency with the proper version (in my case it was Azure.Identity)
And then make sure to add the proper version in your |
While I also can understand that you also fix direct CVE's - please understand that the SqlClient imports some very old outdated stuff with a lot of CVE's. It would help us tremendously to update this package, to keep our projects maintainable. |
Current version 6.2.1 of the Respawn package has a security vulnerability because of an old dependency to Microsoft.Data.SqlClient, that has a dependency to [email protected].
Please update to mitigate this vulnerability.
CVE description: https://nvd.nist.gov/vuln/detail/CVE-2021-24112
The text was updated successfully, but these errors were encountered: