Skip to content

Comments

[17.11] Fix component governance alerts#10520

Merged
MichalPavlik merged 9 commits intovs17.11from
dev/mipavlik/resolve-cg-alerts-17-11
Sep 6, 2024
Merged

[17.11] Fix component governance alerts#10520
MichalPavlik merged 9 commits intovs17.11from
dev/mipavlik/resolve-cg-alerts-17-11

Conversation

@MichalPavlik
Copy link
Member

@MichalPavlik MichalPavlik commented Aug 14, 2024

Fixes CVE-2024-38081, CVE-2024-38095

Context

Some of our dependencies contains vulnerabilities.

Changes Made

I backported changes we already have in main branch - updated Microsoft.IO.Redist package version and pinned System.Formats.Asn1 package version.

Testing

Existing unit test.

Notes

VS 17.11 still uses Microsoft.IO.Redist version 6.0.0, so we need to stick with this version.

@MichalPavlik MichalPavlik requested a review from a team as a code owner August 14, 2024 12:12
@MichalPavlik MichalPavlik changed the base branch from main to vs17.11 August 14, 2024 12:20
@JanKrivanek
Copy link
Member

FYI @marcpopMSFT

@MichalPavlik MichalPavlik merged commit bcaf466 into vs17.11 Sep 6, 2024
@MichalPavlik MichalPavlik deleted the dev/mipavlik/resolve-cg-alerts-17-11 branch September 6, 2024 07:50
@MichalPavlik
Copy link
Member Author

/backport to 17.10

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants