Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update System.Text.Encodings.Web version 4.5.1 #234

Merged
merged 4 commits into from
Nov 26, 2021

Conversation

bekir-ozturk
Copy link
Contributor

@bekir-ozturk bekir-ozturk commented Nov 24, 2021

Patch for the vulnerability dotnet/runtime#49377

This PR updates vulnerable versions of System.Text.Encodings.Web (4.5.0) and Microsoft.AspNetCore.Http (2.1.0) to versions 4.5.1 and 2.1.22 respectively.

Both of these dependencies are referenced by Microsoft.NET.Sdk.Functions, which is likely to be updated to contain the secure versions of these packages. However, as of today, even the latest version of Microsoft.NET.Sdk.Functions package still references the vulnerable versions. Therefore, fix in this PR includes explicitly referencing the packages in the affected projects.

@bekir-ozturk bekir-ozturk merged commit cf67a03 into main Nov 26, 2021
@YuliiaKovalova YuliiaKovalova deleted the dev/bozturk/fix-package-references branch August 29, 2023 12:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants