Skip to content

Update transitive reference to Cryptography.Pkcs library#1183

Merged
tonyqus merged 1 commit into
nissl-lab:masterfrom
robertcoltheart:feature/update-pkcs-lib
Dec 12, 2023
Merged

Update transitive reference to Cryptography.Pkcs library#1183
tonyqus merged 1 commit into
nissl-lab:masterfrom
robertcoltheart:feature/update-pkcs-lib

Conversation

@robertcoltheart
Copy link
Copy Markdown
Contributor

This is a fix to update the transitive reference of System.Security.Cryptography.Pkcs to 6.0.3 to mitigate CVE-2023-29331. By default, the version pulled in is 6.0.1 which contains this vulnerability and causes Aqua Trivy to scan the *.deps.json and raise this error.

Copy link
Copy Markdown
Collaborator

@Bykiev Bykiev left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@tonyqus tonyqus added this to the NPOI 2.7.0 milestone Sep 12, 2023
@robertcoltheart
Copy link
Copy Markdown
Contributor Author

Any update on this?

@waellus
Copy link
Copy Markdown

waellus commented Oct 23, 2023

Hey @tonyqus , should there be a 2.6.3 version to address this security advisory?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants