xmlresolver / xmlresolvercs

A C# implementation of the XML Resolver
Other
4 stars 3 forks source link

NuGet.Frameworks 5.10.0 is not maintained and contains vulnerability #76

Open thpe1000 opened 5 hours ago

thpe1000 commented 5 hours ago

XmlResolver is using NuGet.Frameworks and is subject to vulnerability CVE-2022-30184.

NuGet.Frameworks 5.10.0 is no longer maintained and should be updated as soon as possible.

What is NuGet.Frameworks used for within XmlResolver, can't see any references to that namespace?

ndw commented 4 hours ago

It appears that's a stale dependency 😦 in as much as it appears to build fine without it. I'll push a release with updated dependencies.

Thanks for the report.