serilog-mssql / serilog-sinks-mssqlserver

A Serilog sink that writes events to Microsoft SQL Server and Azure SQL
Apache License 2.0
283 stars 148 forks source link

Vulnerabilities in Microsoft.Data.SqlClient 5.2.1 #547

Closed ckadluba closed 3 months ago

ckadluba commented 3 months ago

Azure.Identity 1.1.3 and Microsoft.Identity.Client 4.60.3 are showing up as vulnerable dependencies of Microsoft.Data.SqlClient 5.2.1, which is a dependency of version 6.6.1 of this package.

image

image

image

image

Originally posted by @MaddMugsy in https://github.com/serilog-mssql/serilog-sinks-mssqlserver/issues/544#issuecomment-2297205374

ckadluba commented 3 months ago

Closing this again. Since things are related, it should be handled in the original issue #544