Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

nuget.packaging 6.3.1 is being flagged by vulnerability scanners #1081

Closed
flcdrg opened this issue Aug 26, 2024 · 3 comments
Closed

nuget.packaging 6.3.1 is being flagged by vulnerability scanners #1081

flcdrg opened this issue Aug 26, 2024 · 3 comments
Milestone

Comments

@flcdrg
Copy link
Contributor

flcdrg commented Aug 26, 2024

I'm building Docker containers that include nbgv 3.6 and the container images are being flagged by JFrog XRay with GHSA-68w7-72jg-6qpp due to the presence of nuget.packaging v6.3.1

Apparently this vulnerabiliy is fixed in versions 5.11.6, 6.0.6, 6.3.4, 6.4.3, 6.6.2, 6.7.1, 6.8.1

If we could upgrade NuGet.PackageManagement to 6.3.4 I think that would mitigate the issue (as I believe that's what is causing NuGet.Packaging to be included)

flcdrg added a commit to flcdrg/Nerdbank.GitVersioning that referenced this issue Aug 26, 2024
@AArnott
Copy link
Collaborator

AArnott commented Aug 26, 2024

Wanna give our CI build a try to see if it addresses the issue?

@AArnott AArnott closed this as completed Aug 26, 2024
@AArnott AArnott added this to the v3.6 milestone Aug 26, 2024
@flcdrg
Copy link
Contributor Author

flcdrg commented Aug 27, 2024

Confirmed that issue is no longer being flagged in the CI build

@AArnott
Copy link
Collaborator

AArnott commented Aug 27, 2024

Watch for 3.6.143 on nuget.org shortly.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants