-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDirectory.Build.props
More file actions
29 lines (28 loc) · 1.51 KB
/
Copy pathDirectory.Build.props
File metadata and controls
29 lines (28 loc) · 1.51 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
<Project>
<!--
Solution-wide transitive package version overrides.
Adds explicit direct references to force vulnerable transitive packages to safe versions.
These packages are pulled in by MongoDB.Driver and Microsoft.AspNetCore.OpenApi.
Update pins when upstream packages stop pulling the old versions.
-->
<PropertyGroup>
<!--
SYSLIB0014: ServicePointManager used for TLS configuration across all services.
Removal requires migrating to SocketsHttpHandler — deferred to a future cleanup task.
ASPDEPR002: WithOpenApi deprecated in ASP.NET 10; still functional.
Migration to new OpenAPI registration pattern is a future task.
-->
<NoWarn>$(NoWarn);SYSLIB0014;ASPDEPR002</NoWarn>
</PropertyGroup>
<ItemGroup>
<!-- MongoDB.Driver transitive: Snappier 1.0.0 (GHSA-pggp-6c3x-2xmx) -->
<PackageReference Include="Snappier" Version="1.3.1" />
<!-- MongoDB.Driver transitive: SharpCompress 0.30.1 (GHSA-6c8g-7p36-r338) -->
<PackageReference Include="SharpCompress" Version="0.50.1" />
<!-- MongoDB.Driver / ASP.NET transitive: Newtonsoft.Json 12.0.3 (GHSA-5crp-9r3c-p9vr) -->
<PackageReference Include="Newtonsoft.Json" Version="13.0.4" />
<!-- Microsoft.AspNetCore.OpenApi transitive: Microsoft.OpenApi 2.0.0 (GHSA-v5pm-xwqc-g5wc)
Must stay in the 2.x range — 3.x has breaking API changes that break the source generator. -->
<PackageReference Include="Microsoft.OpenApi" Version="2.11.0" />
</ItemGroup>
</Project>