Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(dependencies): bump efcore to 8.0.7 #175

Merged
merged 1 commit into from
Jul 25, 2024

Conversation

ntruchsess
Copy link
Contributor

Description

increase efcore version to latest 8.0.7

Why

efcore 8.0.3 has transitive dependency System.Text.Json 8.0.0 which has a security-vulerability that is clasified as high. Upgrade to efcore 8.0.7 implicitly upgrades this dependency to System.Text.Json 8.0.4 which resolves the vulnerability.

Issue

eclipse-tractusx/portal#369

Checklist

Please delete options that are not relevant.

  • I have followed the contributing guidelines
  • I have performed a self-review of my own code
  • I have successfully tested my changes locally
  • I have checked that new and existing tests pass locally with my changes

@ntruchsess ntruchsess changed the base branch from main to release/v1.1.0-rc.2 July 23, 2024 13:32
Copy link

sonarcloud bot commented Jul 23, 2024

@ntruchsess ntruchsess marked this pull request as ready for review July 23, 2024 13:48
@ntruchsess ntruchsess requested a review from evegufy July 23, 2024 13:48
@evegufy evegufy merged commit 27cb2e0 into release/v1.1.0-rc.2 Jul 25, 2024
12 checks passed
@evegufy evegufy deleted the chore/json-text-version branch July 25, 2024 12:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants