Join Slack
Powered by
There is vulnerability in the current NewtonSoft J...
# pact-net
t
Tigran Davtyan
07/07/2023, 12:26 PM
There is vulnerability in the current NewtonSoft Json library version used in
Pact.net
source code, not sure if it is issue. Details under the thread
Tigran Davtyan
07/07/2023, 12:26 PM
https://devhub.checkmarx.com/cve-details/Cx46691637-14e8/
m
Matt (pactflow.io / pact-js / pact-go)
07/07/2023, 2:50 PM
Can't see how a dos issue would be an issue for a test tool. Is it just needing a version bump?
t
Tigran Davtyan
07/07/2023, 2:59 PM
yes it is
m
Matt (pactflow.io / pact-js / pact-go)
07/07/2023, 10:29 PM
Mind opening a pr?
t
Timothy Jones
07/08/2023, 12:21 PM
We should probably enable dependabot for that repo.
☝️ 1
2
Views
Open in Slack
Previous
Next