spark
spark copied to clipboard
[BUG]: Newtonsoft.Json update for CWE-755 vulnerability
https://github.com/advisories/GHSA-5crp-9r3c-p9vr
Describe the bug
Snyk/lgtm et al. are reporting end users' projects vulnerable as a result of a transitive dependency on Newtonsoft.Json 11 in Microsoft.Spark.
To Reproduce
Steps to reproduce the behavior:
- Include
Microsoft.Sparkin a project/solution. - Scan with snyk.io, etc.
(Side note: what happened with this PR? it seemed like it was approved but then got closed spontaneously... https://github.com/dotnet/spark/pull/358)