From 60be76fdcce8782e144d8f9b01e4e6132fcb2d91 Mon Sep 17 00:00:00 2001 From: Aaron Stannard Date: Fri, 19 Jun 2026 20:16:39 +0000 Subject: [PATCH] fix(deps): suppress GHSA-2m69-gcr7-jv3q and pin MessagePack to 2.5.301 - Add MessagePack as direct reference in AppHost so central version pin (2.5.301) takes effect, suppressing GHSA-hv8m-jj95-wg3x (LZ4 decompression DoS from transitive StreamJsonRpc dep) - Add NuGetAuditSuppress for GHSA-2m69-gcr7-jv3q (SQLitePCLRaw.lib.e_sqlite3 CVE-2025-6965) which has no patched version available on NuGet --- Directory.Packages.props | 16 ++++++++++++++++ .../SkillServer.AppHost.csproj | 2 ++ 2 files changed, 18 insertions(+) diff --git a/Directory.Packages.props b/Directory.Packages.props index e71e38d..3574d9b 100644 --- a/Directory.Packages.props +++ b/Directory.Packages.props @@ -40,4 +40,20 @@ + + + + + + + + diff --git a/src/SkillServer.AppHost/SkillServer.AppHost.csproj b/src/SkillServer.AppHost/SkillServer.AppHost.csproj index ce500c8..1483a30 100644 --- a/src/SkillServer.AppHost/SkillServer.AppHost.csproj +++ b/src/SkillServer.AppHost/SkillServer.AppHost.csproj @@ -10,6 +10,8 @@ + +