Skip to content

Conversation

MichalPavlik
Copy link
Member

@MichalPavlik MichalPavlik commented Aug 14, 2024

Fixes CVE-2024-38081, CVE-2024-38095

Context

Some of our dependencies contains vulnerabilities.

Changes Made

I backported changes we already have in main branch - updated Microsoft.IO.Redist package version and pinned System.Formats.Asn1 package version.

Testing

Existing unit test.

Notes

VS 17.11 still uses Microsoft.IO.Redist version 6.0.0, so we need to stick with this version.

@MichalPavlik MichalPavlik requested a review from a team as a code owner August 14, 2024 12:12
@MichalPavlik MichalPavlik changed the base branch from main to vs17.11 August 14, 2024 12:20
@JanKrivanek
Copy link
Member

FYI @marcpopMSFT

@MichalPavlik MichalPavlik merged commit bcaf466 into vs17.11 Sep 6, 2024
10 checks passed
@MichalPavlik MichalPavlik deleted the dev/mipavlik/resolve-cg-alerts-17-11 branch September 6, 2024 07:50
@MichalPavlik
Copy link
Member Author

/backport to 17.10

This was referenced Aug 19, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants