Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Visual Studio detecting Venerability with SixLabours.ImageSharp dependencies #433

Open
bhaveshvakil opened this issue Mar 26, 2024 · 8 comments

Comments

@bhaveshvakil
Copy link

Can someone upgrade this package?

GHSA-65x7-c272-7g7r

As per author, they already fixed the issue but PdfSharpCore is still using old package.

Thanks

@chrisg32
Copy link

chrisg32 commented Apr 8, 2024

@bhaveshvakil If you add package SixLabors.ImageSharp 2.1.7 the error will go away.

This should be closed with #429

@hungphamcrl
Copy link

will PdfSharpCore works with 2.1.8? version 2.1.7 is vulnerable now

@chrisg32
Copy link

@hungphamcrl it should it you add the 2.1.8 package directly.

PR #435 will bump the minimum version to 2.1.8

@TonyValenti
Copy link

PR #427 contains that fix and preserves different versions for legacy builds of the library as well.

@Grynet
Copy link

Grynet commented May 13, 2024

It would be great if this could finally get some attention from the author.

As mentioned solution proposals have already been provided in the linked PR

@jarrabito
Copy link

Is there an ETA on this?

@KBaileyMobilearth
Copy link

2.1.8 is also flagged now.

@kgamecarter
Copy link

Now update to 2.1.9

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

8 participants