Commit ddbe243
fix(security): pin System.Net.Http 4.3.4 + System.Text.RegularExpressions 4.3.1 [APS-19467 APS-19468]
- Add explicit PackageReference pins overriding vulnerable transitive 4.3.0
versions pulled in via NETStandard.Library 1.6.1
- System.Net.Http 4.3.0 -> 4.3.4 (GHSA-7jgj-8wvc-jh57, .NET Core Information Disclosure)
- System.Text.RegularExpressions 4.3.0 -> 4.3.1 (GHSA-cmhx-cq75-c4mj, Regex DoS)
- dotnet list package --vulnerable now reports no vulnerable packages
Resolves: APS-19467, APS-19468
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>1 parent 50a4e33 commit ddbe243
1 file changed
Lines changed: 3 additions & 0 deletions
Lines changed: 3 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
21 | 24 | | |
22 | 25 | | |
23 | 26 | | |
| |||
0 commit comments