KEMBAR78
Enable nuget audit. by TingluoHuang · Pull Request #3615 · actions/runner · GitHub
Skip to content

Conversation

@TingluoHuang
Copy link
Member

@TingluoHuang TingluoHuang requested a review from a team as a code owner December 9, 2024 18:35
@TingluoHuang TingluoHuang merged commit fde5227 into main Dec 9, 2024
9 checks passed
@TingluoHuang TingluoHuang deleted the users/tihuang/nuget branch December 9, 2024 18:49
<PackageReference Include="System.Net.Http" Version="4.3.4" />
<PackageReference Include="System.Text.RegularExpressions" Version="4.3.1" />
<PackageReference Include="System.Private.Uri" Version="4.3.2" />
<PackageReference Include="System.Formats.Asn1" Version="8.0.1" />
Copy link

@hashtagchris hashtagchris Dec 10, 2024

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

8.0.7 or higher is needed, per GHSA-447r-wph3-92pm.

    {
      "package": {
        "ecosystem": "nuget",
        "name": "Microsoft.NetCore.App.Runtime.linux-x64"
      },
      "vulnerable_version_range": ">= 8.0.0, <= 8.0.6",
      "first_patched_version": "8.0.7",
      "vulnerable_functions": [

      ]
    },

Copy link

@hashtagchris hashtagchris Dec 10, 2024

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please ignore, I was looking at the wrong packages in the CVE (Microsoft.NetCore.App.Runtime.*).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants