From cfe6182b4ba4338c327ab4eff699e1847dda251e Mon Sep 17 00:00:00 2001 From: Shad Storhaug Date: Sat, 20 Jan 2024 13:35:41 +0700 Subject: [PATCH 1/2] .build/dependencies.props: Bumped System.Security.Cryptography package to 6.0.1 because of security vulnerabilities found in 4.7.0. See: https://github.com/advisories/GHSA-2m65-m22p-9wjw --- .build/dependencies.props | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.build/dependencies.props b/.build/dependencies.props index e1c974c8ac..557cc3383f 100644 --- a/.build/dependencies.props +++ b/.build/dependencies.props @@ -78,7 +78,7 @@ 4.3.0 5.0.0 4.3.0 - 4.7.0 + 6.0.1 4.3.0 5.0.0 6.1.0 From 0cdfcb9672b6b2d7368e1176cff26aa60fb6b950 Mon Sep 17 00:00:00 2001 From: Shad Storhaug Date: Sat, 20 Jan 2024 13:39:54 +0700 Subject: [PATCH 2/2] .build/dependencies.props: Bumped SharpZipLib to 1.4.2 because of security vulnerabilities found in 1.1.0. See: https://github.com/advisories/GHSA-m22m-h4rf-pwq3 and https://github.com/advisories/GHSA-mm6g-mmq6-53ff --- .build/dependencies.props | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.build/dependencies.props b/.build/dependencies.props index 557cc3383f..a37cc27a3e 100644 --- a/.build/dependencies.props +++ b/.build/dependencies.props @@ -70,7 +70,7 @@ 3.13.1 1.9.1.1 2.7.8 - 1.1.0 + 1.4.2 0.4.1.1 4.5.4 4.3.0