Skip to content

Informational: some used NuGet packages have reported vulnerabilities #16

@vbaderks

Description

@vbaderks

Hi CrypToolProject,

When building your project in Visual Studio 2022 17.12.3 I noticed the following warnings:

NU1902: Package 'BouncyCastle' 1.8.5 has a known moderate severity vulnerability, GHSA-6xx3-rg99-gc3p
NU1903: Package 'Google.Protobuf' 3.6.1 has a known high severity vulnerability, GHSA-77rm-9x9h-xj3g
NU1903: Package 'Newtonsoft.Json' 12.0.3 has a known high severity vulnerability, GHSA-5crp-9r3c-p9vr

Note 1: if needed, I could create a PR to upgrade these NuGet packages to a version that has these issues resolved.
Note 2: Your project doesn't have a Contributing Guidelines or a Security policy listed, so I hope opening an issue like this is ok.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions