Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update "NuGet.*" packages to 6.8.1 (CVE-2024-0057) #330

Merged
merged 1 commit into from
Feb 18, 2024

Conversation

atifaziz
Copy link
Contributor

This PR addresses a critical vulnerability identified in NuGet.Packaging 6.8.0. See CVE-2024-0057, “NuGet Client Security Feature Bypass Vulnerability” for more information.

To be on the conservative side, I've updated all NuGet.* packages to the next patch version 6.8.1 that's not flagged.

For more information on CVE-2024-0057, "NuGet Client Security Feature
Bypass Vulnerability", that affects version 6.8.0, see:

GHSA-68w7-72jg-6qpp
Copy link

codecov bot commented Feb 17, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (e41f024) 77.5% compared to head (80676de) 77.6%.

Additional details and impacted files
@@          Coverage Diff          @@
##            main    #330   +/-   ##
=====================================
  Coverage   77.5%   77.6%           
=====================================
  Files         83      83           
  Lines       5597    5597           
  Branches     735     734    -1     
=====================================
+ Hits        4342    4346    +4     
+ Misses       987     984    -3     
+ Partials     268     267    -1     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@waf waf merged commit 9eff460 into waf:main Feb 18, 2024
3 checks passed
@waf
Copy link
Owner

waf commented Feb 18, 2024

Thank you!

@atifaziz atifaziz deleted the up-nuget-packages branch February 18, 2024 11:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants