Skip to content

Commit a70b2f1

Browse files
committed
1 parent ea95f04 commit a70b2f1

3 files changed

Lines changed: 15 additions & 0 deletions

File tree

Directory.Packages.props

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -46,6 +46,7 @@
4646
<PackageVersion Include="System.IO.Packaging" Version="9.0.0" />
4747
<PackageVersion Include="System.Reflection.Emit" Version="4.7.0" />
4848
<PackageVersion Include="System.Reflection.Metadata" Version="9.0.0" />
49+
<PackageVersion Include="System.Runtime.Caching" Version="8.0.1" />
4950
<PackageVersion Include="Testcontainers" Version="4.0.0" />
5051
<PackageVersion Include="Testcontainers.MsSql" Version="4.0.0" />
5152
</ItemGroup>

src/Dibix.Http.Host/Dibix.Http.Host.csproj

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,13 @@
2424
<PackageReference Include="Microsoft.Data.SqlClient" />
2525
<PackageReference Include="Microsoft.Extensions.Hosting" />
2626
<PackageReference Include="System.IO.Packaging" />
27+
28+
<!--
29+
CVE-2024-43483
30+
Explicitily reference this implicit dependency of Microsoft.Data.SqlClient to force the correct version to be deployed.
31+
Enabling CentralPackageTransitivePinningEnabled would introduce breaking changes for other packages and is avoided during a patch.
32+
-->
33+
<PackageReference Include="System.Runtime.Caching" />
2734
</ItemGroup>
2835

2936
<ItemGroup>

src/Dibix.Worker.Host/Dibix.Worker.Host.csproj

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,13 @@
2424
<PackageReference Include="Microsoft.Extensions.Hosting" />
2525
<PackageReference Include="Microsoft.Extensions.Hosting.WindowsServices" />
2626
<PackageReference Include="Microsoft.Extensions.Http" />
27+
28+
<!--
29+
CVE-2024-43483
30+
Explicitily reference this implicit dependency of Microsoft.Data.SqlClient to force the correct version to be deployed.
31+
Enabling CentralPackageTransitivePinningEnabled would introduce breaking changes for other packages and is avoided during a patch.
32+
-->
33+
<PackageReference Include="System.Runtime.Caching" />
2734
</ItemGroup>
2835

2936
<ItemGroup>

0 commit comments

Comments
 (0)