Skip to content

CG alerts for SBRP #4243

Closed
Closed
@mthalman

Description

@mthalman

While working on the 1ES templates, I got CG errors because the SBRP repo defines packages for two vulnerable packages in the 7.0 branch:

  • System.Drawing.Common.4.7.0
  • System.Security.Cryptography.Xml.4.7.0

System.Drawing.Common.4.7.0 also applies to the 6.0 branch.

These should be upgraded or removed as appropriate.

Metadata

Metadata

Assignees

Labels

area-sbrpSource build reference packages

Type

No type

Projects

Status

Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions