Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Rider warns Server library has known security issues, the CVEs where fixed early 2023 #4

Open
pavlenex opened this issue Feb 26, 2024 · 5 comments
Labels
enhancement New feature or request

Comments

@pavlenex
Copy link
Collaborator

          Another thing, Rider warns me that the used BTCPay Server library has known security issues, the CVEs where fixed early 2023, can you update to a more recent version please?

Screenshot_20240226_121956

Originally posted by @ndeet in #2 (comment)

@pavlenex pavlenex changed the title Another thing, Rider warns me that the used BTCPay Server library has known security issues, the CVEs where fixed early 2023, can you update to a more recent version please? Rider warns Server library has known security issues, the CVEs where fixed early 2023 Feb 26, 2024
@pavlenex pavlenex added the enhancement New feature or request label Feb 26, 2024
@Nisaba
Copy link
Collaborator

Nisaba commented Feb 26, 2024

In Nuget, there is nothing newer than 1.7.3...

image

@pavlenex
Copy link
Collaborator Author

@ndeet ^

@NicolasDorier
Copy link
Member

I will just release a new package... weird

@NicolasDorier
Copy link
Member

NicolasDorier commented Feb 28, 2024

Actually the issue is that nuget confuse CVE about BTCPay project to CVE to the client library... Just bumping the version of the client will not help.

Is there a way to notify whoever gives link advisories to nuget package to check it?

@ndeet
Copy link
Collaborator

ndeet commented Feb 28, 2024

So this means it is just a false alarm from Rider then as those CVE do not affect the client library, right?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

4 participants