Some Dependencies are flagged as vulnerable

未关闭
#179 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
30/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
停滞
技术栈
csharp, github-actions

调研方向

首先定位 sqlmanagementobjects 的依赖项声明,并检查 GitHub Actions Windows runner 在将 NuGetAuditMode 设置为 all 时如何构建项目。如果兼容,请更新存在漏洞的依赖项,然后在启用传递依赖审计的情况下运行项目构建;当构建成功且没有报告的漏洞警告时,即表示完成。

由索引模型根据 Issue 内容生成。

描述

I've only noticed this after the folks at github updated their github action windows runners to use a version of visual studio that has the NuGetAuditMode set to 'all', when the default used to be 'direct'. This means that any transitive Packages with security vulnerabilities are now flagged up as warnings, when previously you'd not see anything if you had -warnaserror set.

The following dependencies of sqlmanagementobjects are flagged as vulnerable, but I'd also like to highlight that a lot of the dependencies referenced in general are massively out of date:

Azure.Identity 1.10.3 (Latest 1.13.1)
Microsoft.Identity.Client 4.56.0 (Latest 4.66.2)
Microsoft.IdentityModel.JsonWebTokens 6.24.0 (Latest 8.2.1)
System.Formats.Asn1 5.0.0 (Latest 9.0.0)
System.IdentityModel.Tokens.Jwt 6.24.0 (latest 8.2.1)

At the moment, I've had to go through my projects and set the nugetauditmode back to direct to replicate the original behaviour so we have our builds back up and running - but obviously we can't stay in this mode forever, especially with a known security issue.

Are there any plans to update the dependencies for sqlmanagementobjects, or am I better off just trying to find an alternative?

Thanks!

主要语言
C#
星标
143
派生
28
PR 合并指标
30 天内没有已合并 PR

贡献指南

这个仓库没有索引到贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

microsoft/sqlmanagementobjects 的其他 Issue

查看 microsoft/sqlmanagementobjects 的全部 Issue

相似的 Issue

更多 C# Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。