Skip to content

Commit 50f9073

Browse files
committed
Fix package version and security vulnerabilities
- Fixed Microsoft.AspNet.WebApi.Client: 6.0.2 (doesn't exist) → 6.0.0 - Added Microsoft.IdentityModel.JsonWebTokens 8.14.0 to fix GHSA-59j7-ghrg-fj52 vulnerability - Added System.IdentityModel.Tokens.Jwt 8.14.0 to fix GHSA-59j7-ghrg-fj52 vulnerability These explicit package references override the vulnerable 7.0.3 versions that were coming in as transitive dependencies.
1 parent a1683ef commit 50f9073

2 files changed

Lines changed: 5 additions & 1 deletion

File tree

src/NosCore.Networking/NosCore.Networking.csproj

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,8 @@
3131
<PackageReference Include="DotNetty.Transport" Version="0.7.6" />
3232
<PackageReference Include="NodaTime" Version="3.2.0" />
3333
<PackageReference Include="NosCore.Packets" Version="15.0.0" />
34+
<PackageReference Include="Microsoft.IdentityModel.JsonWebTokens" Version="8.14.0" />
35+
<PackageReference Include="System.IdentityModel.Tokens.Jwt" Version="8.14.0" />
3436
</ItemGroup>
3537

3638
<ItemGroup>

test/NosCore.Networking.Tests/NosCore.Networking.Tests.csproj

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,12 +24,14 @@
2424
<PrivateAssets>all</PrivateAssets>
2525
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
2626
</PackageReference>
27-
<PackageReference Include="Microsoft.AspNet.WebApi.Client" Version="6.0.2" />
27+
<PackageReference Include="Microsoft.AspNet.WebApi.Client" Version="6.0.0" />
2828
<PackageReference Include="Microsoft.NET.Test.Sdk" Version="18.0.1" />
2929
<PackageReference Include="Moq" Version="4.20.72" />
3030
<PackageReference Include="MSTest.TestAdapter" Version="4.0.2" />
3131
<PackageReference Include="MSTest.TestFramework" Version="4.0.2" />
3232
<PackageReference Include="NodaTime.Testing" Version="3.2.0" />
33+
<PackageReference Include="Microsoft.IdentityModel.JsonWebTokens" Version="8.14.0" />
34+
<PackageReference Include="System.IdentityModel.Tokens.Jwt" Version="8.14.0" />
3335
</ItemGroup>
3436

3537
<ItemGroup>

0 commit comments

Comments
 (0)