Skip to content

Commit df7c324

Browse files
claudiamurialdoBeta Bot
authored andcommitted
Cherry pick branch 'genexuslabs:chore/security-package-updates' into beta
1 parent c33543b commit df7c324

16 files changed

Lines changed: 35 additions & 32 deletions

File tree

dotnet/src/dotnetcore/DynService/OData/DynServiceOData.csproj

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,8 @@
1414
<ItemGroup>
1515
<PackageReference Include="Microsoft.Extensions.Configuration" Version="8.0.0" />
1616
<PackageReference Include="GeneXus.Odata.Client" Version="5.2.3.8" />
17+
<!-- Override GeneXus.Odata.Client's vulnerable transitive Microsoft.Data.OData 5.8.3 -->
18+
<PackageReference Include="Microsoft.Data.OData" Version="5.8.4" />
1719
</ItemGroup>
1820
<ItemGroup>
1921
<ProjectReference Include="..\..\GxClasses\GxClasses.csproj" />

dotnet/src/dotnetcore/GxClasses/GxClasses.csproj

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -141,10 +141,10 @@
141141
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
142142
</PackageReference>
143143
<PackageReference Include="Microsoft.Extensions.Logging.ApplicationInsights" Version="2.22.0" PrivateAssets="ALL" />
144-
<PackageReference Include="Azure.Monitor.OpenTelemetry.Exporter" Version="1.1.0" PrivateAssets="All" />
144+
<PackageReference Include="Azure.Monitor.OpenTelemetry.Exporter" Version="1.3.0" PrivateAssets="All" />
145145
<PackageReference Include="MimeTypesMap" Version="1.0.9" />
146-
<PackageReference Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" Version="1.7.0" PrivateAssets="All" />
147-
<PackageReference Include="OpenTelemetry.Exporter.Console" Version="1.7.0" PrivateAssets="All" />
146+
<PackageReference Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" Version="1.8.1" PrivateAssets="All" />
147+
<PackageReference Include="OpenTelemetry.Exporter.Console" Version="1.8.1" PrivateAssets="All" />
148148
<PackageReference Include="Pgvector" Version="0.3.0" PrivateAssets="All" />
149149
<PackageReference Include="MySqlConnector" Version="2.5.0" PrivateAssets="All" />
150150
<PackageReference Include="NetTopologySuite" Version="2.0.0" />

dotnet/src/dotnetcore/GxMail/GxMail.csproj

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -71,7 +71,7 @@
7171
<PackageReference Include="MailKit" Version="4.16.0" />
7272
<PackageReference Include="Microsoft.Exchange.WebServices" Version="2.2.0" />
7373
<PackageReference Include="MimeKit" Version="4.16.0" />
74-
<PackageReference Include="Microsoft.Identity.Client" Version="4.61.3" />
74+
<PackageReference Include="Microsoft.Identity.Client" Version="4.84.0" />
7575
<PackageReference Include="OpenPop" Version="2.0.6.2" />
7676
<PackageReference Include="Org.Mentalis.Security" Version="1.0.0" />
7777
</ItemGroup>

dotnet/src/dotnetcore/GxNetCoreStartup/GxNetCoreStartup.csproj

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -20,13 +20,13 @@
2020
<PackageReference Include="Microsoft.Data.SqlClient" Version="5.1.6" />
2121
<PackageReference Include="Microsoft.Extensions.Caching.SqlServer" Version="3.1.3" />
2222
<PackageReference Include="Microsoft.Extensions.Caching.StackExchangeRedis" Version="8.0.26" />
23-
<PackageReference Include="Microsoft.Identity.Client" Version="4.61.3" />
23+
<PackageReference Include="Microsoft.Identity.Client" Version="4.84.0" />
2424
<PackageReference Include="Swashbuckle.AspNetCore.SwaggerUI" Version="6.5.0" />
2525

26-
<PackageReference Include="Azure.Identity" Version="1.11.4" PrivateAssets="All" />
27-
<PackageReference Include="Azure.Monitor.OpenTelemetry.Exporter" Version="1.1.0" PrivateAssets="All" />
28-
<PackageReference Include="OpenTelemetry" Version="1.7.0" PrivateAssets="All" />
29-
<PackageReference Include="OpenTelemetry.Exporter.Console" Version="1.7.0" PrivateAssets="All" />
26+
<PackageReference Include="Azure.Identity" Version="1.17.1" PrivateAssets="All" />
27+
<PackageReference Include="Azure.Monitor.OpenTelemetry.Exporter" Version="1.3.0" PrivateAssets="All" />
28+
<PackageReference Include="OpenTelemetry" Version="1.8.1" PrivateAssets="All" />
29+
<PackageReference Include="OpenTelemetry.Exporter.Console" Version="1.8.1" PrivateAssets="All" />
3030
<PackageReference Include="Microsoft.Extensions.Logging.ApplicationInsights" Version="2.22.0" PrivateAssets="All" />
3131

3232
<PackageReference Include="itext7" Version="8.0.0" PrivateAssets="All" />

dotnet/src/dotnetcore/GxOffice/GxOffice.csproj

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,8 +42,11 @@
4242

4343
<ItemGroup>
4444
<PackageReference Include="BouncyCastle.Cryptography" Version="2.6.2" />
45-
<PackageReference Include="NPOI" Version="2.7.3" />
45+
<PackageReference Include="NPOI" Version="2.8.0" />
4646
<PackageReference Include="Microsoft.Extensions.Configuration" Version="8.0.0" />
47+
<!-- Override NPOI's vulnerable transitive System.Security.Cryptography.Xml -->
48+
<PackageReference Include="System.Security.Cryptography.Xml" Version="8.0.3" Condition="'$(TargetFramework)' == 'net8.0'" />
49+
<PackageReference Include="System.Security.Cryptography.Xml" Version="10.0.6" Condition="'$(TargetFramework)' == 'net10.0'" />
4750
</ItemGroup>
4851

4952
<ItemGroup>

dotnet/src/dotnetcore/Providers/OpenTelemetry/Diagnostics/GXOtel.Diagnostics/GXOtel.Diagnostics.csproj

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
</PropertyGroup>
1313

1414
<ItemGroup>
15-
<PackageReference Include="OpenTelemetry.Exporter.Console" Version="1.7.0" />
15+
<PackageReference Include="OpenTelemetry.Exporter.Console" Version="1.8.1" />
1616
</ItemGroup>
1717

1818
<ItemGroup>

dotnet/src/dotnetcore/Providers/OpenTelemetry/OpenTelemetry/GeneXus.OpenTelemetry.csproj

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -9,9 +9,9 @@
99
</PropertyGroup>
1010

1111
<ItemGroup>
12-
<PackageReference Include="OpenTelemetry.Exporter.Console" Version="1.7.0" />
13-
<PackageReference Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" Version="1.7.0" />
14-
<PackageReference Include="OpenTelemetry.Extensions.Hosting" Version="1.7.0" />
12+
<PackageReference Include="OpenTelemetry.Exporter.Console" Version="1.8.1" />
13+
<PackageReference Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" Version="1.8.1" />
14+
<PackageReference Include="OpenTelemetry.Extensions.Hosting" Version="1.8.1" />
1515
<PackageReference Include="OpenTelemetry.Instrumentation.AspNetCore" Version="1.8.1" />
1616
<PackageReference Include="OpenTelemetry.Instrumentation.Http" Version="1.8.1" />
1717
<PackageReference Include="OpenTelemetry.Instrumentation.Runtime" Version="1.7.0" />

dotnet/src/dotnetcore/Providers/OpenTelemetry/OpenTelemetryAzureMonitor/GeneXus.OpenTelemetry.Azure.AppInsights.csproj

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -11,13 +11,13 @@
1111
</PropertyGroup>
1212
<ItemGroup>
1313

14-
<PackageReference Include="Azure.Identity" Version="1.11.4" />
15-
<PackageReference Include="Azure.Monitor.OpenTelemetry.Exporter" Version="1.1.0" />
14+
<PackageReference Include="Azure.Identity" Version="1.17.1" />
15+
<PackageReference Include="Azure.Monitor.OpenTelemetry.Exporter" Version="1.3.0" />
1616
<PackageReference Include="log4net.Ext.Json" Version="3.0.3" />
1717
<PackageReference Include="Microsoft.ApplicationInsights.Log4NetAppender" Version="2.22.0" />
18-
19-
<PackageReference Include="OpenTelemetry" Version="1.7.0" />
20-
<PackageReference Include="OpenTelemetry.Exporter.Console" Version="1.7.0" />
18+
19+
<PackageReference Include="OpenTelemetry" Version="1.8.1" />
20+
<PackageReference Include="OpenTelemetry.Exporter.Console" Version="1.8.1" />
2121

2222
</ItemGroup>
2323
<ItemGroup>

dotnet/src/dotnetframework/GxMail/GxMail.csproj

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@
1111
<ItemGroup>
1212
<PackageReference Include="MailKit" Version="4.16.0" />
1313
<PackageReference Include="MimeKit" Version="4.16.0" />
14-
<PackageReference Include="Microsoft.Identity.Client" Version="4.60.4" />
14+
<PackageReference Include="Microsoft.Identity.Client" Version="4.84.0" />
1515
<PackageReference Include="OpenPop.NET" Version="2.0.6.1120" />
1616
<PackageReference Include="Org.Mentalis.Security" Version="1.0.0" />
1717
<PackageReference Condition="'$(SignAssembly)'=='true'" Include="StrongNamer" Version="0.2.5" />

dotnet/src/dotnetframework/GxOffice/GxOffice.csproj

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99
<ItemGroup>
1010
<PackageReference Include="BouncyCastle.Cryptography" Version="2.6.2" />
1111
<PackageReference Include="EPPlus" Version="4.5.3.2" />
12-
<PackageReference Include="NPOI" Version="2.7.3" />
12+
<PackageReference Include="NPOI" Version="2.8.0" />
1313
<PackageReference Include="Microsoft.Extensions.Configuration" Version="8.0.0" />
1414
</ItemGroup>
1515

0 commit comments

Comments
 (0)