Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Timeline for 2.22.0 release #2792

Closed
oleksandr-didyk opened this issue Jun 26, 2023 · 6 comments
Closed

Timeline for 2.22.0 release #2792

oleksandr-didyk opened this issue Jun 26, 2023 · 6 comments

Comments

@oleksandr-didyk
Copy link

Given that the existing 2.22.0 GitHub milestone is 20+ days behind schedule, is there any planned release date for this version that can be shared?

This is mostly in regards to a fix for a licensing issue - #2670

As mentioned in the issue above, the project is used in .NET source-code and having a proprietary license would mean that .NET is not allowed to use it. The fix is currently present in a beta release of the project, but .NET would not take a dependency on a beta package, thus the need for a full release to be publicly available for us to be able to consume the fix.

@TimothyMothra
Copy link
Member

Hi @oleksandr-didyk, I will follow up on this.

Can you help me understand why this is a blocker for your team?
We're discussing this fix here: #2671
The affected file is only used in unit tests, and not in the shipped sdk.

@dstj
Copy link

dstj commented Jun 27, 2023

Not to mention the fix for CVE-2021-24112 that sits in 2.22 as well.

@oleksandr-didyk
Copy link
Author

Hey @TimothyMothra, thank you for taking care of this!

The affected file is only used in unit tests, and not in the shipped sdk.

Currently the package is part of the VMR -> https://github.com/dotnet/dotnet
VMR is intended for open-source use and everything included in it should be open-source compatible

Due to source-build limitations we are carrying a submodule of Application.Insights, pointing to the version that repositories in .NET utilize - https://github.com/dotnet/dotnet/tree/main/src/source-build-externals/src. We can only point to the version that is used by the repos & the repos would only use a release version. As such, we would need the fix in question to be released for it to take effect in the VMR

@mthalman
Copy link
Member

@TimothyMothra - Any update on this?

@TimothyMothra
Copy link
Member

@mthalman
@oleksandr-didyk

No ETA at the moment.

@xiang17
Copy link
Member

xiang17 commented Dec 6, 2023

Not to mention the fix for CVE-2021-24112 that sits in 2.22 as well.

This is released now (PR #2832). New version is at: https://www.nuget.org/packages/Microsoft.ApplicationInsights/2.22.0.

The fix for CVE-2021-24112 in System.Drawing.Common (#2707) is also included.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants