Skip to content

Patch advisories#1023

Merged
davidmrdavid merged 4 commits intomainfrom
dajusto/patch-advisories
Jan 2, 2024
Merged

Patch advisories#1023
davidmrdavid merged 4 commits intomainfrom
dajusto/patch-advisories

Conversation

@davidmrdavid
Copy link
Collaborator

@davidmrdavid davidmrdavid commented Jan 2, 2024

Replaces: #1020

As of recently, building the DTFx project failed with errors of the following kind:

"Warning as Error: Package has a known high severity vulnerability" and it points to this advisory: "

The warnings were for:

In response, I made the following changes:

  • Upgraded System.Data.SqlClient to 4.8.5. This is only used in our test project, so it's safe.
  • Suppressed the warning on our Newtonsoft.Json version 7.0.1 dependency, which we use on the net462 TFM for backwards compatibility with Functions V1. I chose to suppress it to minimize breaking customers, and because Functions V1 is soon to be EOL.
  • Finally, I removed redundant references to Newtonsoft.Json in our test projects, and in DTFx.AzureStorage. We already make receive Newtonsoft.Json transitively, so having these dependencies only adds to our maintanance burden afaict.

Note: the warnings still appear for DTFx.ServiceBus and DTFx.AzureServiceFabric. I did not apply my changes there as I know those projects are maintained by separate teams. I can contribute a PR to their projects once this one is merged.

@davidmrdavid davidmrdavid merged commit f45e43c into main Jan 2, 2024
@davidmrdavid davidmrdavid deleted the dajusto/patch-advisories branch January 2, 2024 21:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants