Skip to content

Commit

Permalink
Fixed System.* vulnerabilities
Browse files Browse the repository at this point in the history
Fixed vulnerabilites reported by NuGet audit in System.Net.Http and System.Text.RegularExpressions by removing any references to System.* version 4.* packages as recommended here: https://devblogs.microsoft.com/nuget/nugetaudit-2-0-elevating-security-and-trust-in-package-management/#system-net-http-and-system-text-regularexpressions

Related issue: serilog-mssql#544
  • Loading branch information
ckadluba committed Aug 20, 2024
1 parent 4cf4544 commit 18669d6
Show file tree
Hide file tree
Showing 3 changed files with 1 addition and 17 deletions.
9 changes: 1 addition & 8 deletions Directory.Packages.props
Original file line number Diff line number Diff line change
Expand Up @@ -4,13 +4,6 @@
</PropertyGroup>
<ItemGroup>
<PackageVersion Include="Microsoft.NET.Test.Sdk" Version="17.8.0" />
<PackageVersion Include="System.Configuration.ConfigurationManager" Version="6.0.1" />
<PackageVersion Include="System.Collections" Version="4.3.0" />
<PackageVersion Include="System.IO.FileSystem.Primitives" Version="4.3.0" />
<PackageVersion Include="System.Resources.ResourceManager" Version="4.3.0" />
<PackageVersion Include="System.Runtime.Extensions" Version="4.3.1" />
<PackageVersion Include="System.Runtime.InteropServices" Version="4.3.0" />
<PackageVersion Include="System.Text.Encoding.Extensions" Version="4.3.0" />
<PackageVersion Include="Microsoft.Data.SqlClient" Version="5.2.1" />
<PackageVersion Include="Microsoft.Extensions.Configuration" Version="6.0.1" />
<PackageVersion Include="Microsoft.Extensions.Configuration.Json" Version="6.0.0" />
Expand All @@ -28,4 +21,4 @@
<PackageVersion Include="Serilog.Settings.Configuration" Version="3.4.0" />
<PackageVersion Include="Serilog.Sinks.PeriodicBatching" Version="3.1.0" />
</ItemGroup>
</Project>
</Project>
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,6 @@
</ItemGroup>

<ItemGroup Condition=" '$(TargetFramework)' == 'net6.0' Or '$(TargetFramework)' == 'net472' Or '$(TargetFramework)' == 'net462' ">
<PackageReference Include="System.Configuration.ConfigurationManager" />
<Compile Include="Configuration\Extensions\Hybrid\**\*.cs" />
<Compile Include="Configuration\Implementations\Microsoft.Extensions.Configuration\**\*.cs" />
<Compile Include="Configuration\Implementations\System.Configuration\**\*.cs" />
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -38,21 +38,13 @@
</ItemGroup>

<ItemGroup Condition=" '$(TargetFramework)' == 'net472' Or '$(TargetFramework)' == 'net462' ">
<Reference Include="System" />
<Reference Include="System.Transactions" />
<Reference Include="Microsoft.CSharp" />
<Compile Include="Configuration\Extensions\Hybrid\**\*.cs" />
<Compile Include="Configuration\Implementations\Microsoft.Extensions.Configuration\**\*.cs" />
<Compile Include="Configuration\Implementations\System.Configuration\**\*.cs" />
</ItemGroup>

<ItemGroup Condition=" '$(TargetFramework)' == 'net6.0' ">
<PackageReference Include="System.Collections" />
<PackageReference Include="System.Runtime.InteropServices" />
<PackageReference Include="System.Runtime.Extensions" />
<PackageReference Include="System.IO.FileSystem.Primitives" />
<PackageReference Include="System.Resources.ResourceManager" />
<PackageReference Include="System.Text.Encoding.Extensions" />
<PackageReference Include="coverlet.collector">
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
<PrivateAssets>all</PrivateAssets>
Expand Down

0 comments on commit 18669d6

Please sign in to comment.