Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security warnings about usage of NuGet.Protocol v6.0 #2760

Open
Numpsy opened this issue Sep 2, 2023 · 5 comments
Open

Security warnings about usage of NuGet.Protocol v6.0 #2760

Numpsy opened this issue Sep 2, 2023 · 5 comments

Comments

@Numpsy
Copy link
Contributor

Numpsy commented Sep 2, 2023

Description

I created a CI build using FAKE 6 which also gets run through a Mend analysis, and it raised a warning about references to NuGet.Protocol v 6.0 which has known security vulnerabilities.

Looking at the listing for NuGet.Protocol on nuget.org, it seems that the 6.0.0 versions of all those libraries have actually been delisted due to issues, and several of the updates versions are listed as having issues themselves.

Given the delisting, I think it would be good to bump the version used?

Repro steps

Version 6.0 seems to be specified at https://github.com/fsprojects/FAKE/blob/13e30330cae0597aed6154a95a06d21716b18de3/paket.lock#L825C1-L825C9

Known workarounds

As i'm running the build via a .fsproj file, I can locally update the referances to a newer version if I have to.

Related information

  • Indications of severity
    Nuget says the vulnerability is 'high severity'

  • Version of FAKE (4.X, 5.X, 6.x)
    6.0

@github-actions
Copy link

github-actions bot commented Sep 2, 2023

Welcome to the FAKE community! Thank you so much for creating your first issue and therefore improving the project!

@xperiandri
Copy link
Collaborator

@Numpsy will you prepare a PR?

@Numpsy
Copy link
Contributor Author

Numpsy commented Oct 1, 2023

That was the intent of #2761 / #2764

@xperiandri
Copy link
Collaborator

Approved

@Numpsy
Copy link
Contributor Author

Numpsy commented Feb 15, 2024

This stuff is never ending, versions 6.7.0 is showing as having issues now: GHSA-68w7-72jg-6qpp :-(

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants