Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pin Microsoft.IO.Redist in net472 tests #921

Merged
merged 1 commit into from
Feb 5, 2025

Conversation

DaveTryon
Copy link
Contributor

CVE-2024-38081 calls out a vulnerability in Microsoft.IO.Redist 6.0.0, which is fixed in 6.0.1. We already use 6.1.0 in our shipping bits, but the net472 tests are stuck on an older version of Microsoft.Build, which still uses version 6.0.0 of Microsoft.IO.Redist. This adds net472-specific pins to the test projects, so that CG will no longer complain about this package.

@DaveTryon DaveTryon requested a review from a team as a code owner February 4, 2025 20:47
@DaveTryon
Copy link
Contributor Author

/azp run

@DaveTryon DaveTryon merged commit 20f4360 into main Feb 5, 2025
4 checks passed
@DaveTryon DaveTryon deleted the DaveTryon/pin-Microsoft.IO.Redist-in-tests branch February 5, 2025 16:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants