Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Update transitive reference to Cryptography.Pkcs library #1183

Merged
merged 1 commit into from
Dec 12, 2023

Conversation

robertcoltheart
Copy link
Contributor

This is a fix to update the transitive reference of System.Security.Cryptography.Pkcs to 6.0.3 to mitigate CVE-2023-29331. By default, the version pulled in is 6.0.1 which contains this vulnerability and causes Aqua Trivy to scan the *.deps.json and raise this error.

Copy link
Collaborator

@Bykiev Bykiev left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@tonyqus tonyqus added this to the NPOI 2.7.0 milestone Sep 12, 2023
@robertcoltheart
Copy link
Contributor Author

Any update on this?

@waellus
Copy link

waellus commented Oct 23, 2023

Hey @tonyqus , should there be a 2.6.3 version to address this security advisory?

# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants