Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use of vulnerable STJ 8.0.4 package in SBRP #4928

Closed
mthalman opened this issue Mar 3, 2025 · 1 comment
Closed

Use of vulnerable STJ 8.0.4 package in SBRP #4928

mthalman opened this issue Mar 3, 2025 · 1 comment
Assignees
Labels
area-sbrp Source build reference packages ops-monitor Issues created/handled by the source build monitor role

Comments

@mthalman
Copy link
Member

mthalman commented Mar 3, 2025

Component detection has an alert (internal link) for System.Text.Json 8.0.4 in the SBRP repo.

The detected paths are:

/s/artifacts/bin/PackageSourceGenerator/nuget.protocol/6.12.1/nuget.protocol.6.12.1.csproj
/s/src/referencePackages/src/system.text.json/8.0.4/system.text.json.nuspec

This shows up for the Windows leg only, it seems. It's not clear why this is showing up since those paths are specified to be ignored: https://github.com/dotnet/source-build-reference-packages/blob/e136f061bbd92453c21393c907d5ff546e8f1a20/azure-pipelines/builds/ci.yml#L29-L33

@mthalman mthalman added the ops-monitor Issues created/handled by the source build monitor role label Mar 3, 2025
@MichaelSimons MichaelSimons added area-sbrp Source build reference packages and removed untriaged labels Mar 6, 2025
@MichaelSimons MichaelSimons self-assigned this Mar 6, 2025
@MichaelSimons MichaelSimons moved this from Backlog to 10.0 Preview 3 in .NET Source Build Mar 6, 2025
@MichaelSimons
Copy link
Member

The CG alert has been resolved and the report is currently clean.

@github-project-automation github-project-automation bot moved this from 10.0 Preview 3 to Done in .NET Source Build Mar 19, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area-sbrp Source build reference packages ops-monitor Issues created/handled by the source build monitor role
Projects
Status: Done
Development

No branches or pull requests

2 participants