Skip to content

Commit 371efe6

Browse files
authored
Bump MongoDB.Driver + fix vulnerable dependencies (#5070)
1 parent 5972afe commit 371efe6

4 files changed

Lines changed: 8 additions & 4 deletions

File tree

build/LibraryVersions.g.cs

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -108,7 +108,7 @@ public static partial class LibraryVersion
108108
new("3.0.0", supportedFrameworks: [ "net10.0", "net9.0", "net8.0", "net472" ]),
109109
new("3.5.0", supportedFrameworks: [ "net10.0", "net9.0", "net8.0", "net472" ]),
110110
new("3.7.0", supportedFrameworks: [ "net10.0", "net9.0", "net8.0", "net472" ]),
111-
new("3.8.0", supportedFrameworks: [ "net10.0", "net9.0", "net8.0", "net472" ]),
111+
new("3.8.1", supportedFrameworks: [ "net10.0", "net9.0", "net8.0", "net472" ]),
112112
]
113113
},
114114
{

test/Directory.Packages.props

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@
3333
<PackageVersion Include="Microsoft.Extensions.Logging.Abstractions" Version="10.0.7" />
3434
<PackageVersion Include="Microsoft.Extensions.Options" Version="10.0.7" />
3535
<PackageVersion Include="Microsoft.NET.Test.Sdk" Version="18.5.1" />
36-
<PackageVersion Include="MongoDB.Driver" Version="3.8.0" />
36+
<PackageVersion Include="MongoDB.Driver" Version="3.8.1" />
3737
<PackageVersion Include="NSubstitute" Version="5.3.0" />
3838
<PackageVersion Include="MySql.Data" Version="9.7.0" />
3939
<PackageVersion Include="MySqlConnector" Version="2.5.0" />
@@ -51,6 +51,7 @@
5151
<PackageVersion Include="Quartz.Extensions.DependencyInjection" Version="3.18.1" />
5252
<PackageVersion Include="Quartz.Extensions.Hosting" Version="3.18.1" />
5353
<PackageVersion Include="RabbitMQ.Client" Version="7.2.1" />
54+
<PackageVersion Include="SharpCompress" Version="0.48.1" />
5455
<PackageVersion Include="Snappier" Version="1.3.1" />
5556
<PackageVersion Include="StackExchange.Redis" Version="3.0.2-preview" />
5657
<PackageVersion Include="StrongNamer" Version="0.2.5" />

test/IntegrationTests/LibraryVersions.g.cs

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -226,7 +226,7 @@ public static TheoryData<string> MongoDB
226226
"3.7.0",
227227
#endif
228228
#if NET10_0 || NET9_0 || NET8_0 || NET462
229-
"3.8.0",
229+
"3.8.1",
230230
#endif
231231
#endif
232232
];

test/test-applications/integrations/TestApplication.MongoDB/TestApplication.MongoDB.csproj

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,10 @@
1313
<PackageReference Include="MongoDB.Driver" VersionOverride="$(LibraryVersion)" />
1414
<!-- Snappier is transitive dependency of MongoDB.Driver. All versions up to 3.8.0 references v1.0.0
1515
All versions pruor to 1.3.1 are vulnerable for https://github.com/advisories/GHSA-pggp-6c3x-2xmx -->
16-
<PackageReference Include="Snappier" />
16+
<PackageReference Include="Snappier" Condition="'$(OS)' == 'Windows_NT' and '$(LibraryVersion)' != '' and $([MSBuild]::VersionLessThan('$(LibraryVersion)', '3.8.1'))" />
17+
<!-- SharpCompress is a transitive dependency of MongoDB.Driver. Version up to 0.47.4 are vulnerable.
18+
for https://github.com/advisories/GHSA-6c8g-7p36-r338 -->
19+
<PackageReference Include="SharpCompress" />
1720
</ItemGroup>
1821

1922
</Project>

0 commit comments

Comments
 (0)