DotNetZip.Semverd icon indicating copy to clipboard operation
DotNetZip.Semverd copied to clipboard

Transitive dependency security issue Microsoft NetCore Platforms 3.1.1

Open AFract opened this issue 2 years ago • 0 comments

Hello,

DotNetZip is a great library and I am happy to see it's still maintained.

However, when importing DotNetZip.Semverd (last version) in a .Net 7 project, I have this notice : image

The related details are available here : https://devhub.checkmarx.com/cve-details/CVE-2021-31957/

Do you plan an update of the dependencies to prevent this please ?

Thank you very much

AFract avatar Nov 09 '23 08:11 AFract