Skip to content

Commit ddbe243

Browse files
fix(security): pin System.Net.Http 4.3.4 + System.Text.RegularExpressions 4.3.1 [APS-19467 APS-19468]
- Add explicit PackageReference pins overriding vulnerable transitive 4.3.0 versions pulled in via NETStandard.Library 1.6.1 - System.Net.Http 4.3.0 -> 4.3.4 (GHSA-7jgj-8wvc-jh57, .NET Core Information Disclosure) - System.Text.RegularExpressions 4.3.0 -> 4.3.1 (GHSA-cmhx-cq75-c4mj, Regex DoS) - dotnet list package --vulnerable now reports no vulnerable packages Resolves: APS-19467, APS-19468 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
1 parent 50a4e33 commit ddbe243

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

NunitPlaywrightBrowserstack.Tests/NunitPlaywrightBrowserstack.Tests.csproj

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,9 @@
1818
<PackageReference Include="NUnit" Version="4.3.2" />
1919
<PackageReference Include="NUnit.Analyzers" Version="4.6.0" />
2020
<PackageReference Include="NUnit3TestAdapter" Version="4.6.0" />
21+
<!-- Security pins: override vulnerable transitive 4.3.0 (via NETStandard.Library 1.6.1). APS-19467 / APS-19468 -->
22+
<PackageReference Include="System.Net.Http" Version="4.3.4" />
23+
<PackageReference Include="System.Text.RegularExpressions" Version="4.3.1" />
2124
</ItemGroup>
2225

2326
<ItemGroup>

0 commit comments

Comments
 (0)