Skip to content

Commit a28cf30

Browse files
petrsvihlikclaude
andcommitted
Override vulnerable transitive dependencies with safe versions
Statiq.Web pulls in several packages with known vulnerabilities. Added explicit version overrides to resolve all NU190x warnings: - Azure.Identity 1.19.0 - Microsoft.Build.Tasks.Core 18.4.0 - Microsoft.Data.SqlClient 6.1.4 - Microsoft.IdentityModel.JsonWebTokens / System.IdentityModel.Tokens.Jwt 8.16.0 - Microsoft.Rest.ClientRuntime 2.3.24 (capped at <3.0.0 for Azure.Search compat) - Newtonsoft.Json 13.0.4 - System.Data.SqlClient 4.9.1 - System.DirectoryServices.Protocols / System.Drawing.Common / System.Security.Cryptography.Xml 10.0.5 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
1 parent 1632100 commit a28cf30

1 file changed

Lines changed: 15 additions & 0 deletions

File tree

PetrSvihlik.Com.csproj

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,21 @@
1212
<PackageReference Include="Statiq.Web" Version="1.0.0-beta.60" />
1313
</ItemGroup>
1414

15+
<!-- Vulnerability overrides for transitive dependencies -->
16+
<ItemGroup>
17+
<PackageReference Include="Azure.Identity" Version="1.19.0" />
18+
<PackageReference Include="Microsoft.Build.Tasks.Core" Version="18.4.0" />
19+
<PackageReference Include="Microsoft.Data.SqlClient" Version="6.1.4" />
20+
<PackageReference Include="Microsoft.IdentityModel.JsonWebTokens" Version="8.16.0" />
21+
<PackageReference Include="Microsoft.Rest.ClientRuntime" Version="2.3.24" />
22+
<PackageReference Include="Newtonsoft.Json" Version="13.0.4" />
23+
<PackageReference Include="System.Data.SqlClient" Version="4.9.1" />
24+
<PackageReference Include="System.DirectoryServices.Protocols" Version="10.0.5" />
25+
<PackageReference Include="System.Drawing.Common" Version="10.0.5" />
26+
<PackageReference Include="System.IdentityModel.Tokens.Jwt" Version="8.16.0" />
27+
<PackageReference Include="System.Security.Cryptography.Xml" Version="10.0.5" />
28+
</ItemGroup>
29+
1530
<ItemGroup>
1631
<Compile Remove="extensionas\**" />
1732
<Compile Remove="input\**" />

0 commit comments

Comments
 (0)