Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security: Upgrade two NuGets (and one dependency) that have been flagged #8517

Merged
merged 1 commit into from
Jul 5, 2023

Conversation

cybertyche
Copy link
Contributor

@cybertyche cybertyche commented Jul 1, 2023

Azure Pipelines is recording the following security vulnerability:
CST-E has determined that this component is not generally safe to use.|Azure.Data.Tables 12.6.1 |Critical

This PR updates that NuGet (and its dependent package Azure.Core. It also updates System.Data.SqlClient, which is being flagged in Visual Studio as a security risk.

Microsoft Reviewers: Open in CodeFlow

@ReubenBond
Copy link
Member

Thanks, @cyberenerally. We typically recommend that end users update their own dependencies rather than relying on transitive dependencies to update them, but I will merge this anyway.

@ReubenBond ReubenBond merged commit a9c8310 into dotnet:main Jul 5, 2023
@cybertyche cybertyche deleted the jamest/nuget branch July 5, 2023 17:48
@cybertyche
Copy link
Contributor Author

We typically recommend that end users update their own dependencies rather than relying on transitive dependencies to update them, but I will merge this anyway.

Ah! Interesting. For the SQL Server one, I think that makes sense. The Azure DataTables one was showing as a security risk in the VSO pipeline itself as critical, so my guess is if it wasn't flagged yet for sending you nag mails, it would eventually. That's what happened with my old team in Bing.

@github-actions github-actions bot locked and limited conversation to collaborators Dec 2, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants