Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Directory.Packages.props
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@
<PackageVersion Include="Microsoft.Extensions.Caching.StackExchangeRedis" Version="8.0.0" />
<PackageVersion Include="Microsoft.Extensions.Configuration.Abstractions" Version="8.0.0" />
<PackageVersion Include="Microsoft.Extensions.DependencyInjection.Abstractions" Version="8.0.2" />
<PackageVersion Include="Microsoft.Extensions.Hosting.Abstractions" Version="9.0.0" />
<PackageVersion Include="Microsoft.Extensions.Hosting.Abstractions" Version="10.0.5" />
<PackageVersion Include="Microsoft.Extensions.Logging.Abstractions" Version="8.0.3" />
<!-- Dataverse packages -->
<PackageVersion Include="Microsoft.CrmSdk.CoreAssemblies" Version="9.0.2.56" />
Expand Down
6 changes: 3 additions & 3 deletions src/server/api/Sprk.Bff.Api/Sprk.Bff.Api.csproj
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@
<PackageReference Include="Azure.AI.DocumentIntelligence" Version="1.0.0" />
<!-- Azure.AI.OpenAI 2.8.0-beta.1: restores compat with OpenAI 2.8.0 (2.1.0 threw MissingMethodException on SerializedAdditionalRawData) -->
<PackageReference Include="Azure.AI.OpenAI" Version="2.8.0-beta.1" />
<PackageReference Include="Azure.Identity" Version="1.17.1" />
<PackageReference Include="Azure.Identity" Version="1.20.0" />
<PackageReference Include="Azure.Storage.Blobs" Version="12.27.0" />
<PackageReference Include="Azure.Messaging.ServiceBus" Version="7.18.1" />
<PackageReference Include="Azure.Search.Documents" Version="11.6.0" />
Expand All @@ -46,7 +46,7 @@
<!-- Microsoft.Extensions.Caching.Abstractions 10.0.3: bumped from 10.0.1 to satisfy Microsoft.Extensions.AI 10.3.0 dependency chain -->
<PackageReference Include="Microsoft.Extensions.Caching.Abstractions" Version="10.0.3" />
<PackageReference Include="Microsoft.Extensions.Caching.StackExchangeRedis" Version="10.0.1" />
<PackageReference Include="Microsoft.Extensions.Hosting.Abstractions" Version="8.0.0" />
<PackageReference Include="Microsoft.Extensions.Hosting.Abstractions" Version="10.0.5" />

<!-- Microsoft Graph SDK v5.x (CRITICAL - must be 5.x or higher) -->
<PackageReference Include="Microsoft.Graph" Version="5.101.0" />
Expand All @@ -61,7 +61,7 @@

<!-- Microsoft Identity (CRITICAL - must be 3.x or higher) -->
<!-- Identity.Web 3.8.2+ fixes CVE-2025-32016; requires Identity.Client >= 4.70.0 -->
<PackageReference Include="Microsoft.Identity.Client" Version="4.79.2" />
<PackageReference Include="Microsoft.Identity.Client" Version="4.83.3" />
<PackageReference Include="Microsoft.Identity.Web" Version="4.3.0" />
<PackageReference Include="Microsoft.Identity.Web.MicrosoftGraph" Version="4.3.0" />
<!-- MimeKit 4.15.1: fixes CVE-2026-30227 (CRLF injection in SMTP envelope address) -->
Expand Down
1 change: 1 addition & 0 deletions src/server/shared/Spaarke.Core/Spaarke.Core.csproj
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@
</ItemGroup>

<ItemGroup>
<PackageReference Include="Microsoft.Extensions.Hosting.Abstractions" />
<ProjectReference Include="..\Spaarke.Dataverse\Spaarke.Dataverse.csproj" />
</ItemGroup>

Expand Down
13 changes: 7 additions & 6 deletions src/server/shared/Spaarke.Dataverse/Spaarke.Dataverse.csproj
Original file line number Diff line number Diff line change
Expand Up @@ -9,19 +9,20 @@
</PropertyGroup>

<ItemGroup>
<PackageReference Include="Azure.Core" Version="1.50.0" />
<PackageReference Include="Azure.Identity" Version="1.17.1" />
<PackageReference Include="Azure.Core" Version="1.52.0" />
<PackageReference Include="Azure.Identity" Version="1.20.0" />
<PackageReference Include="Microsoft.Extensions.Caching.Abstractions" Version="10.0.1" />
<PackageReference Include="Microsoft.Extensions.Configuration.Abstractions" Version="8.0.0" />
<PackageReference Include="Microsoft.Extensions.Logging.Abstractions" Version="8.0.3" />
<PackageReference Include="Microsoft.Identity.Client" Version="4.79.2" />
<PackageReference Include="Microsoft.Extensions.Configuration.Abstractions" Version="10.0.5" />
<PackageReference Include="Microsoft.Extensions.Hosting.Abstractions" />
<PackageReference Include="Microsoft.Extensions.Logging.Abstractions" Version="10.0.5" />
<PackageReference Include="Microsoft.Identity.Client" Version="4.83.3" />
<PackageReference Include="Microsoft.PowerPlatform.Dataverse.Client" Version="1.1.32" />

<!-- Security: Override vulnerable transitive dependencies -->
<!-- CVE-2024-38095 (HIGH): System.Formats.Asn1 6.0.0 → 8.0.1 -->
<PackageReference Include="System.Formats.Asn1" Version="8.0.1" />
<!-- CVE-2024-30105 (HIGH): System.Text.Json 7.0.3 → 8.0.5 -->
<PackageReference Include="System.Text.Json" Version="8.0.5" />
<PackageReference Include="System.Text.Json" Version="10.0.3" />
<!-- CVE-2023-29331 (HIGH): System.Security.Cryptography.Pkcs 6.0.1 → 8.0.1 -->
<PackageReference Include="System.Security.Cryptography.Pkcs" Version="8.0.1" />
<!-- CVE-2019-0820 (HIGH): System.Text.RegularExpressions 4.3.0 → 4.3.1 -->
Expand Down