Skip to content

Conversation

@mend-for-github-com
Copy link

@mend-for-github-com mend-for-github-com bot commented Feb 5, 2024

This PR contains the following updates:

Package Type Update Change
MessagePack nuget minor 1.7.3.4 -> 1.9.3

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability
Medium Medium 4.8 CVE-2020-5234

Release Notes

MessagePack-CSharp/MessagePack-CSharp (MessagePack)

v1.9.3

Changes

🔒 Security fixes are included in this release. Read more in our security advisory.

No other changes are included in this release relative to v1.8

v1.8.80

  • Adjust assembly version from 1.8.74.32478 to simply 1.8.0.0 (#​604)
  • Update System.Threading.Tasks.Extensions dependency to 4.5.3 (#​610)
  • Publish symbols in snupkg archives to nuget.org (#​624)

v1.8.74

Very few changes since 1.7, but now building from a more serviceable branch.

v1.7.3.7: (security fix)

This servicing release fixes a security issue with the deserializer to prevent unbounded memory allocations from relatively small MessagePack payloads.


  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Feb 5, 2024
@mend-for-github-com mend-for-github-com bot changed the title Update dependency MessagePack to v1.9.3 Update dependency MessagePack to 1.9.3 Feb 25, 2025
@mend-for-github-com mend-for-github-com bot changed the title Update dependency MessagePack to 1.9.3 Update dependency MessagePack to 1.9.3 - autoclosed May 13, 2025
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/messagepack-1.x branch May 13, 2025 15:44
@mend-for-github-com mend-for-github-com bot changed the title Update dependency MessagePack to 1.9.3 - autoclosed Update dependency MessagePack to 1.9.3 May 14, 2025
@mend-for-github-com mend-for-github-com bot reopened this May 14, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/messagepack-1.x branch from 0abd721 to 1001bf2 Compare May 14, 2025 18:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant