-
Notifications
You must be signed in to change notification settings - Fork 67
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Is Release 4.12 available on nuget.org? 4.08 Flagged as Security issue #249
Comments
+1 |
Same issue here. When can 4.0.12 be released to nuget to mitigate this vulnerability? |
@adrianvmsft Is there any way to release the 4.0.12 nuget? |
Bump. The source code for tag v4.0.12 has Newtonsoft.Json 13.0.1 The Newtonsoft.Json DLL packaged on nuget is still showing 9.0.1. (Scanners are also seeing the version as 9.0.1, as @IanGoddard mentioned) |
Any updates on this |
Still looking for a 4.0.12 release to NuGet. |
+1, no solution for non-Visual Studio user I assume? |
Appears that the https://github.com/microsoft/slow-cheetah/tree/v4.0.50 release includes 7ae268b, which updates Newtonsoft to 13.0.01 4.0.52 hasn't been pushed to NuGet, but for the purposes of this issue, since 4.0.50 includes the fix I'd call it closed as soon as someone can get to it. |
SlowCheetah 4.0.8 is the only version on nuget.org which comes packages with newtonsoft.json 9.0.1. This is being flagged by static code analysis tools as a security vulnerability.
This is fixed in release 4.0.12 however, this has not been pushed to nuget and therefore means that SlowCheetah 4.0.8 and 3.2.26 are both not allowed to be used by teams that maintaining security best practises against software vulnerabilities.
The release folder contains source code for 4.0.12 but the released version on nuget is 4.0.8 and there are no beta versions available.
The text was updated successfully, but these errors were encountered: