microsoft / Msdyn365.Commerce.Online

Dynamics 365 Commerce online project
Other
49 stars 41 forks source link

Critical vulnerabilities in packages #57

Closed DShalima closed 1 year ago

DShalima commented 2 years ago

There is 20 Critical vulnerabilities in packages right now. This two as example

Screenshot 2022-07-15 at 13 57 10 Screenshot 2022-07-15 at 13 56 33
mkelan commented 1 year ago

We review the critical vulnerabilities periodically and act on them. Depending on whether the vulnerability is applicable to us (based on whether we use that vulnerable code and how that dependency is used etc.) we either fix them or close them (if its not applicable). Also we dont normally back port these vulnerability fixes, its often fixed forward.