Update dependency coverlet.collector to v6 #46
Security Report
3 new vulnerabilities were introduced in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2024-30105Path to dependency file: /tests/SimCube.Spartan.Tests/SimCube.Spartan.Tests.csproj Path to vulnerable library: /home/wss-scanner/.nuget/packages/system.text.json/7.0.0/system.text.json.7.0.0.nupkg Dependency Hierarchy: -> microsoft.aspnetcore.mvc.testing.7.0.1.nupkg (Root Library) -> microsoft.extensions.hosting.7.0.0.nupkg -> microsoft.extensions.logging.eventsource.7.0.0.nupkg -> ❌ system.text.json.7.0.0.nupkg (Vulnerable Library) |
High | 7.5 | system.text.json.7.0.0.nupkg | Upgrade to version: System.Text.Json - 8.0.4 | None |
CVE-2019-0820Path to dependency file: /tests/SimCube.Spartan.Tests/SimCube.Spartan.Tests.csproj Path to vulnerable library: /opt/containerbase/tools/dotnet/sdk/NuGetFallbackFolder/system.text.regularexpressions/4.3.0/system.text.regularexpressions.4.3.0.nupkg Dependency Hierarchy: -> xunit.2.4.2.nupkg (Root Library) -> xunit.assert.2.4.2.nupkg -> netstandard.library.1.6.1.nupkg -> system.xml.xdocument.4.3.0.nupkg -> system.xml.readerwriter.4.3.0.nupkg -> ❌ system.text.regularexpressions.4.3.0.nupkg (Vulnerable Library) |
High | 7.5 | system.text.regularexpressions.4.3.0.nupkg | Upgrade to version: System.Text.RegularExpressions - 4.3.1 | None |
CVE-2018-8292Path to dependency file: /tests/SimCube.Spartan.Tests/SimCube.Spartan.Tests.csproj Path to vulnerable library: /opt/containerbase/tools/dotnet/sdk/NuGetFallbackFolder/system.net.http/4.3.0/system.net.http.4.3.0.nupkg Dependency Hierarchy: -> xunit.2.4.2.nupkg (Root Library) -> xunit.assert.2.4.2.nupkg -> netstandard.library.1.6.1.nupkg -> ❌ system.net.http.4.3.0.nupkg (Vulnerable Library) |
Medium | 5.3 | system.net.http.4.3.0.nupkg | Upgrade to version: System.Net.Http - 4.3.4;Microsoft.PowerShell.Commands.Utility - 6.1.0-rc.1 | None |
Base branch total remaining vulnerabilities: 0
Base branch commit: null
Total libraries scanned: 145
Scan token: c908d9a1abc34cc3b026f082d7c67ad5