Skip to content

Commit 9a855d3

Browse files
adrianhallahall
andauthored
fix: resolve transitive package vulnerabilities and update non-breaking dependencies (#460) (#466)
Resolves the SharpCompress (NU1902) and Snappier (NU1903) transitive vulnerabilities by bumping MongoDB.Driver (3.6.0 -> 3.9.0) and Testcontainers (4.10.0 -> 4.12.0), which now pull in SharpCompress 0.48.1 and Snappier 1.3.1. Also updates all other patch/minor dependencies. Breaking (major) upgrades deferred to #465. Co-authored-by: ahall <ahall@cloudflare.com>
1 parent 0e388fd commit 9a855d3

1 file changed

Lines changed: 12 additions & 12 deletions

File tree

Directory.Packages.props

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -4,20 +4,20 @@
44
<CentralPackageTransitivePinningEnabled>true</CentralPackageTransitivePinningEnabled>
55
</PropertyGroup>
66
<PropertyGroup>
7-
<DotNetVersion>10.0.3</DotNetVersion>
8-
<EFCoreVersion>10.0.3</EFCoreVersion>
9-
<TestContainersVersion>4.10.0</TestContainersVersion>
7+
<DotNetVersion>10.0.9</DotNetVersion>
8+
<EFCoreVersion>10.0.9</EFCoreVersion>
9+
<TestContainersVersion>4.12.0</TestContainersVersion>
1010
<ODataVersion>8.4.3</ODataVersion>
1111
</PropertyGroup>
1212
<ItemGroup>
1313
<PackageVersion Include="AutoMapper" Version="16.1.1" />
14-
<PackageVersion Include="AwesomeAssertions" Version="9.3.0" />
14+
<PackageVersion Include="AwesomeAssertions" Version="9.4.0" />
1515
<PackageVersion Include="Azure.Identity" Version="1.17.1" />
1616
<PackageVersion Include="LiteDB" Version="5.0.21" />
1717
<PackageVersion Include="Microsoft.AspNetCore.Mvc.Testing" Version="$(DotNetVersion)" />
1818
<PackageVersion Include="Microsoft.AspNetCore.OData" Version="9.4.1" />
1919
<PackageVersion Include="Microsoft.AspNetCore.OpenApi" Version="$(DotNetVersion)" />
20-
<PackageVersion Include="Microsoft.Azure.Cosmos" Version="3.57.0" />
20+
<PackageVersion Include="Microsoft.Azure.Cosmos" Version="3.61.0" />
2121
<PackageVersion Include="Microsoft.EntityFrameworkCore" Version="$(EFCoreVersion)" />
2222
<PackageVersion Include="Microsoft.EntityFrameworkCore.Cosmos" Version="$(EFCoreVersion)" />
2323
<PackageVersion Include="Microsoft.EntityFrameworkCore.InMemory" Version="$(EFCoreVersion)" />
@@ -29,16 +29,16 @@
2929
<PackageVersion Include="Microsoft.Extensions.DependencyInjection.Abstractions" Version="$(DotNetVersion)" />
3030
<PackageVersion Include="Microsoft.Extensions.Http" Version="$(DotNetVersion)" />
3131
<PackageVersion Include="Microsoft.Extensions.Logging.Abstractions" Version="$(DotNetVersion)" />
32-
<PackageVersion Include="Microsoft.NET.Test.Sdk" Version="18.0.1" />
32+
<PackageVersion Include="Microsoft.NET.Test.Sdk" Version="18.6.0" />
3333
<PackageVersion Include="Microsoft.OData.Core" Version="$(ODataVersion)" />
34-
<PackageVersion Include="Microsoft.SourceLink.GitHub" Version="10.0.103" />
34+
<PackageVersion Include="Microsoft.SourceLink.GitHub" Version="10.0.300" />
3535
<PackageVersion Include="Microsoft.Spatial" Version="8.4.3" />
3636
<PackageVersion Include="Newtonsoft.Json" Version="13.0.4" />
37-
<PackageVersion Include="MongoDB.Driver" Version="3.6.0" />
37+
<PackageVersion Include="MongoDB.Driver" Version="3.9.0" />
3838
<PackageVersion Include="NSubstitute" Version="5.3.0" />
39-
<PackageVersion Include="NSwag.AspNetCore" Version="14.6.3" />
40-
<PackageVersion Include="Npgsql.EntityFrameworkCore.PostgreSQL" Version="10.0.0" />
41-
<PackageVersion Include="Swashbuckle.AspNetCore" Version="10.0.1" />
39+
<PackageVersion Include="NSwag.AspNetCore" Version="14.7.1" />
40+
<PackageVersion Include="Npgsql.EntityFrameworkCore.PostgreSQL" Version="10.0.2" />
41+
<PackageVersion Include="Swashbuckle.AspNetCore" Version="10.2.1" />
4242
<PackageVersion Include="System.Formats.Asn1" Version="$(DotNetVersion)" />
4343
<PackageVersion Include="System.Linq.Async" Version="7.0.0" />
4444
<PackageVersion Include="System.Net.Http" Version="4.3.4" />
@@ -55,6 +55,6 @@
5555
<PackageVersion Include="Ulid" Version="1.4.1" />
5656
<!-- Do not change XUnit.Combinatorial to v2 (xUnit v2 compatibility) -->
5757
<PackageVersion Include="XUnit.Combinatorial" Version="1.6.24" />
58-
<PackageVersion Include="XUnit.SkippableFact" Version="1.5.23" />
58+
<PackageVersion Include="XUnit.SkippableFact" Version="1.5.61" />
5959
</ItemGroup>
6060
</Project>

0 commit comments

Comments
 (0)