Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update transitive reference to Cryptography.Pkcs library #1183

Merged
merged 1 commit into from
Dec 12, 2023

Conversation

robertcoltheart
Copy link
Contributor

This is a fix to update the transitive reference of System.Security.Cryptography.Pkcs to 6.0.3 to mitigate CVE-2023-29331. By default, the version pulled in is 6.0.1 which contains this vulnerability and causes Aqua Trivy to scan the *.deps.json and raise this error.

Copy link
Collaborator

@Bykiev Bykiev left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@tonyqus tonyqus added this to the NPOI 2.7.0 milestone Sep 12, 2023
@robertcoltheart
Copy link
Contributor Author

Any update on this?

@waellus
Copy link

waellus commented Oct 23, 2023

Hey @tonyqus , should there be a 2.6.3 version to address this security advisory?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants