Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump dependencies to fix security vulnerabilities #15

Merged
merged 6 commits into from
Aug 30, 2022

Conversation

mishamyte
Copy link
Contributor

Hello @jbogard,

Want to use your project as a part of OTLP stack.
So due to abandonment of existing PR, updated some deps & pipelines.

Closes #13, #14

@jbogard
Copy link
Owner

jbogard commented Aug 29, 2022

Build failure :(

@mishamyte
Copy link
Contributor Author

Failure caused by a known issue on a MongoDB Driver team side.
It it caused by unmanaged compression libs, used by MongoDB driver.
They say that it is fixed in the next driver release (2.18.0), but I don't have any timelines.

So I'm looking for a workarounds for now, but hope that release will be soon)

@mishamyte
Copy link
Contributor Author

mishamyte commented Aug 29, 2022

Looked through the MongoDB.Driver.Core repository. They supress it with <NoWarn>NU5100</NoWarn>, so seems legit)

@jbogard
Copy link
Owner

jbogard commented Aug 30, 2022

Ah that makes sense, thanks!

@mishamyte
Copy link
Contributor Author

I think it could be merged.

Also I'm going to investigate is this package up to date or should be adjusted to the latest spec/practices of pckgs and contribute, if it will be needed

@jbogard jbogard merged commit d82ab5e into jbogard:master Aug 30, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Security Vulnerabilities with version 1.1.0
2 participants