Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion Directory.Packages.props
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,8 @@
<PackageVersion Include="Microsoft.Win32.SystemEvents" Version="10.0.12" />
<PackageVersion Include="System.Configuration.ConfigurationManager" Version="10.0.12" />
<PackageVersion Include="System.Data.Odbc" Version="10.0.12" />
<!-- Direct reference only to lift the vulnerable 4.7.0 that Stimulsoft 2022.1.2 pulls in -->
<!-- Direct reference only to lift the vulnerable 4.7.0 that Stimulsoft 2022.1.2 pulls in
(Desktop.Reporting, plus the test project so its restore never fetches 4.7.0) -->
<PackageVersion Include="System.Data.SqlClient" Version="4.9.1" />

<PackageVersion Include="System.ServiceProcess.ServiceController" Version="10.0.12" />
Expand Down
7 changes: 7 additions & 0 deletions tests/BAUERGROUP.Shared.Test/BAUERGROUP.Shared.Test.csproj
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,13 @@
<PackageReference Include="Moq" />
<PackageReference Include="xunit" />
<PackageReference Include="xunit.runner.visualstudio" />
<!-- Not used by the tests. NuGet only skips a transitive dependency without fetching it
when the project being restored references that package directly; a direct reference
in a ProjectReference (Desktop.Reporting) does not count. Without this line, restoring
this project downloads the vulnerable System.Data.SqlClient 4.7.0 that Stimulsoft
2022.1.2 requests into ./Packages, where the dependency graph reports it
(GHSA-98g6-xh36-x2p7, GHSA-8g2p-5pqh-5jmc), although 4.9.1 wins resolution. -->
<PackageReference Include="System.Data.SqlClient" />
</ItemGroup>

<ItemGroup>
Expand Down
Loading