-
Notifications
You must be signed in to change notification settings - Fork 3.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[C#] Security issue in JSON dependency #44463
Comments
Odd; it's been days since Dependabot has sent a PR for this in the arrow-adbc repo. Maybe it's backed up for Arrow? This is an easy enough change -- just update to 8.0.5 -- and if no one else does it I'll be able to do it later today. |
@CurtHagenlocher is this required for 18.0.0? |
Yes, we should update this for 18.0.0. |
@raulcd I take that back, the dependency in question is used only in test code so it probably doesn't need to be a blocker for 18.0.0. |
Thanks, that makes sense. There's a couple more issues found that will make us create a new release candidate. |
I should have looked more closely at this yesterday. The warning is not coming on the main branch (which was indeed fixed due to Dependabot) but probably from the release branch? In any event, the PR which addressed this in main was #44343. |
Thanks @CurtHagenlocher. I've added the |
It seems that C# integration tests have started failing due to a security issue having been reported for
System.Text.Json
Component(s)
C#
The text was updated successfully, but these errors were encountered: