Skip to content

Conversation

@DaveTryon
Copy link
Contributor

CVE-2024-38081 calls out a vulnerability in Microsoft.IO.Redist 6.0.0, which is fixed in 6.0.1. We already use 6.1.0 in our shipping bits, but the net472 tests are stuck on an older version of Microsoft.Build, which still uses version 6.0.0 of Microsoft.IO.Redist. This adds net472-specific pins to the test projects, so that CG will no longer complain about this package.

@DaveTryon DaveTryon requested a review from a team as a code owner February 4, 2025 20:47
@DaveTryon
Copy link
Contributor Author

/azp run

@DaveTryon DaveTryon merged commit 20f4360 into main Feb 5, 2025
4 checks passed
@DaveTryon DaveTryon deleted the DaveTryon/pin-Microsoft.IO.Redist-in-tests branch February 5, 2025 16:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants