auth0 / auth0-oidc-client-net

OIDC Client for .NET Desktop and Mobile applications
https://auth0.github.io/auth0-oidc-client-net/
Apache License 2.0
84 stars 48 forks source link

Bump Microsoft.IdentityModel.Protocols.OpenIdConnect #325

Closed frederikprijck closed 4 months ago

frederikprijck commented 4 months ago

Fix a Snyk issue regarding Microsoft.IdentityModel.Protocols.OpenIdConnect.

✗ Resource Exhaustion [Medium Severity][https://security.snyk.io/vuln/SNYK-DOTNET-MICROSOFTIDENTITYMODELJSONWEBTOKENS-6148656] in Microsoft.IdentityModel.JsonWebTokens@6.12.2
    introduced by Microsoft.IdentityModel.Protocols.OpenIdConnect@6.12.2 > System.IdentityModel.Tokens.Jwt@6.12.2 > Microsoft.IdentityModel.JsonWebTokens@6.12.2
  This issue was fixed in versions: 5.7.0, 6.34.0, 7.1.2
✗ Resource Exhaustion [Medium Severity][https://security.snyk.io/vuln/SNYK-DOTNET-SYSTEMIDENTITYMODELTOKENSJWT-[61](https://github.com/auth0/auth0-oidc-client-net/actions/runs/8821836705/job/24219430757?pr=324#step:11:62)48655] in System.IdentityModel.Tokens.Jwt@6.12.2
    introduced by Microsoft.IdentityModel.Protocols.OpenIdConnect@6.12.2 > System.IdentityModel.Tokens.Jwt@6.12.2
  This issue was fixed in versions: 5.7.0, 6.34.0, 7.1.2

Also bump Android to 32 to fix CI, which should be fine as it's the lowest supported version as per https://dotnet.microsoft.com/en-us/platform/support/policy/xamarin