Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[release/8.0] Bump Azure.Identity to 1.11.0 #3660

Merged
merged 1 commit into from
Apr 12, 2024

Conversation

danmoseley
Copy link
Member

@danmoseley danmoseley commented Apr 12, 2024

CVE-2024-29992

https://dnceng.visualstudio.com/internal/_componentGovernance/dotnet-aspire?_a=alerts&typeId=20652644&alerts-view-option=active

@eerhardt there are various transitive references to this from other dependencies, as the link above shows. Is this change sufficient to pull everything to 1.11.0?

Microsoft Reviewers: Open in CodeFlow

@dotnet-issue-labeler dotnet-issue-labeler bot added the area-integrations Issues pertaining to Aspire Integrations packages label Apr 12, 2024
@danmoseley danmoseley requested a review from eerhardt April 12, 2024 16:56
@dotnet-policy-service dotnet-policy-service bot added the Servicing-consider Issue for next servicing release review label Apr 12, 2024
@danmoseley danmoseley changed the title Bump Azure.Identity to 1.11.0 [release/8.0] Bump Azure.Identity to 1.11.0 Apr 12, 2024
@danmoseley danmoseley added Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Apr 12, 2024
@danmoseley
Copy link
Member Author

Approving my own thing as it's a necessary change...

@eerhardt eerhardt merged commit 1032a55 into dotnet:release/8.0 Apr 12, 2024
6 of 8 checks passed
@github-actions github-actions bot locked and limited conversation to collaborators May 13, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
area-integrations Issues pertaining to Aspire Integrations packages Servicing-approved Approved for servicing release
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants