Replies: 1 comment 2 replies
-
AutoFixture does not have a direct dependency on So they're likely transient dependencies of You should likely stop seeing the warning if you would install the latest preview version on the MyGet feed, since that one targets |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I've been running Snyk on my project (.net 6) and I've been getting multiple vulnerabilities from AutoFixture mostly because of System.Net.Http@4.3.0 and System.Text.RegularExpressions@4.3.0. Are there any plans to update System.Net.Http or any other ideas on how to fix this?
Examples of the vulnerabilities are:
Denial of Service (DoS)
Improper Certificate Validation
Privilege Escalation
Regular Expression Denial of Service (ReDoS)
Beta Was this translation helpful? Give feedback.
All reactions