Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update NuGet packages #31316

Open
Jay-o-Way opened this issue Feb 6, 2024 · 9 comments
Open

Update NuGet packages #31316

Jay-o-Way opened this issue Feb 6, 2024 · 9 comments
Labels
Area-Build Issues pertaining to the build system, CI, infrastructure, meta

Comments

@Jay-o-Way
Copy link
Collaborator

Jay-o-Way commented Feb 6, 2024

System.Net.Http ⚠️

Image

Update 📈

  • WPF-UI 3.0 (latest) Check changes to see what we can improve in PowerToys.
  • WinUI-EX v2.2.0 --> 2.3.3 Check changes to see what we can improve in PowerToys.
  • System.IO.Abstractions 17.2.3 --> 20.0.15 changes
  • UnitsNet 4.415 --> 5.43 changes

Check for unused 🗑️

  • FZ Editor
    • ModernWpfUI: update 0.9.4 to 0.9.6 (from 6/2022) or change to WPF-UI or to WinUI3?
  • Settings project??
    Image
@Jay-o-Way Jay-o-Way converted this from a draft issue Feb 6, 2024
@Jay-o-Way

This comment has been minimized.

@Jay-o-Way Jay-o-Way added the Area-Build Issues pertaining to the build system, CI, infrastructure, meta label Apr 20, 2024
@Jay-o-Way
Copy link
Collaborator Author

@jaimecbernardo who can i ping for this?

@jaimecbernardo
Copy link
Collaborator

Ah, looks like we need to fix before .NET 9 hits in November.

@jaimecbernardo
Copy link
Collaborator

Regarding unused extensions, there were some that we needed to make sure dependencies follow the same versions after the flattening.

@Jay-o-Way
Copy link
Collaborator Author

Nobody mentioning the vulnerability issue?

@drawbyperpetual
Copy link
Collaborator

@Jay-o-Way: I'm currently looking into the BinaryFormatter deprecation / security issue. Regarding the System.Net.Http issue, could you indicate where you see the dependency? I don't see us taking any NuGet dependency on System.Net.Http in the entire solution.

image

@Jay-o-Way
Copy link
Collaborator Author

Jay-o-Way commented May 19, 2024

@drawbyperpetual thanks. System.Net.Http is unused in SvgPreviewHandler (FYI @zanseb) and is used in OobeWhatsNew - seemingly to create a way to link/show release notes. (HttpClient and such)
image

CC @jaimecbernardo and @lncubus

@drawbyperpetual
Copy link
Collaborator

@Jay-o-Way: Yes, System.Net.Http is indeed used there but not via a vulnerable NuGet package, but rather via a framework dependency on .NET Core 8. Where's the vulnerability there?

@Jay-o-Way
Copy link
Collaborator Author

@drawbyperpetual I just encountered the warning one day. Not an expert on the usage details 😇

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Area-Build Issues pertaining to the build system, CI, infrastructure, meta
Projects
Status: To do
Development

No branches or pull requests

3 participants