Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

A transient package contains security vulnerability #350

Open
mindaugasveblauskas opened this issue Nov 20, 2024 · 1 comment
Open

A transient package contains security vulnerability #350

mindaugasveblauskas opened this issue Nov 20, 2024 · 1 comment

Comments

@mindaugasveblauskas
Copy link

According to Visual Studio (v17.12.1), the package protobuf-net.Grpc has a security vulnerability, because one of its transient packages are flagged. Even though I'm using the latest version of protobuf-net.Grpc 1.2.2, it uses protobuf-net 2.4.8, but not 3.2.30 as stated at https://github.com/protobuf-net/protobuf-net.Grpc/blob/1.2.2/Directory.Packages.props

The project which uses protobuf-net.Grpc 1.2.2 targets .net 8.

image

@mgravell
Copy link
Member

Yes, we can update the refs. However, this is ultimately a false positive in that a: none of that code is relevant to this lib, and b: you can apply later packages yourself locally. But agree: we should fix the refs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants