Repository navigation
DYN-10890: Update 3rd party package versions (Newtonsoft.Json, RestSharp, WebView2) - #17383
Open
edwin-vasquez-ucaldas wants to merge 5 commits into
Open
edwin-vasquez-ucaldas wants to merge 5 commits into
edwin-vasquez-ucaldas wants to merge 5 commits into
Conversation
…s part of the Global Launch 3rd party component review
There was a problem hiding this comment.
See the ticket for this pull request: https://autodesk.atlassian.net/browse/DYN-10890
jasonstratton
left a comment
Contributor
There was a problem hiding this comment.
- There are a few Dependabot PRs still pending. Please review them and either merge them or close them if they are no longer needed.
- We need to check with Revit and C3D to see what version of WebView2 they are using and pin the same version.
- RestSharp: use 112.1.0 instead of 114.0.0. Greg is still built against 112 (as your Jira comment notes)
- Newtonsoft.Json 13.0.4: is good
- please test these three:
-- System.Configuration.ConfigurationManager: 5.0.0 → 10.0.12
-- System.Drawing.Common: 6.0.0 → 10.0.12, to match .NET 10.
-- HtmlSanitizer: 5.0.372 → 9.2.1039. This fixes GHSA-j92c-7v7g-gj3f and GHSA-43cp-6p3q-2pc4 and brings AngleSharp to 1.7.2, which fixes GHSA-pgww-w46g-26qg. It's a major-version jump, so please check that Md2Html still builds and sanitizes correctly. This replaces Dependabot PR #17068, which can be closed afterwards. - Magick.NET-Q8-AnyCPU and Magick.NET.Core: 14.12.0 → 14.17.2. Everything below 14.15.0 has open advisories.
Contributor
Author
|
Thanks @jasonstratton, regarding your previous comment
|
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Purpose
Update third-party components to their latest stable versions for Global Launch. Each version was checked against the GitHub Advisory DB through the NuGet vulnerability feed.
Updated the listed versions in
ABOUT.txt.Not changed in this PR:
LiveChartsCore.SkiaSharpView.WPF2.0.0-rc3.3 and is past the advisory fix (GHSA-j7hp-h8jx-5ppr, fixed in 2.88.6). Moving to SkiaSharp 3.x requires upgrading LiveCharts to 2.0.5, which is a major-version change for the chart nodes.Declarations
Check these if you believe they are true
Release Notes
N/A
Reviewers
@jasonstratton @RobertGlobant20
@jnealb
FYIs