System.Private.Uri 4.3.0 Blackduck security High vulnerability #644

Open
opened 2025-12-29 08:31:44 +01:00 by adam · 4 comments
Owner

Originally created by @pavlo-khomiak-philips on GitHub (Nov 1, 2024).

Originally assigned to: @StefH on GitHub.

During blackduck scan action it detect some security and licence issues with internal dependencies.

image

System.Private.Uri 4.3.0 - High security vulnerability
Microsoft.NETCore.Platforms/1.1.1 - Medium license risk
Microsoft.NETCore.Targets1.1.3 - Medium license risk

Do you plan to update dependencies ?

Originally created by @pavlo-khomiak-philips on GitHub (Nov 1, 2024). Originally assigned to: @StefH on GitHub. During blackduck scan action it detect some security and licence issues with internal dependencies. ![image](https://github.com/user-attachments/assets/86a6369d-4713-41a7-95f5-25bfed78dd57) System.Private.Uri 4.3.0 - High security vulnerability Microsoft.NETCore.Platforms/1.1.1 - Medium license risk Microsoft.NETCore.Targets1.1.3 - Medium license risk Do you plan to update dependencies ?
adam added the bug label 2025-12-29 08:31:44 +01:00
Author
Owner

@StefH commented on GitHub (Nov 1, 2024):

I will take a look

@StefH commented on GitHub (Nov 1, 2024): I will take a look
Author
Owner

@StefH commented on GitHub (Nov 9, 2024):

https://github.com/WireMock-Net/WireMock.Net/pull/1206

@StefH commented on GitHub (Nov 9, 2024): https://github.com/WireMock-Net/WireMock.Net/pull/1206
Author
Owner

@StefH commented on GitHub (Nov 9, 2024):

@pavlo-khomiak-philips
I cannot see which package uses this one.
Do you have more details?

@StefH commented on GitHub (Nov 9, 2024): @pavlo-khomiak-philips I cannot see which package uses this one. Do you have more details?
Author
Owner

@StefH commented on GitHub (Jun 28, 2025):

@pavlo-khomiak-philips
I cannot see which package uses this one.
Do you have more details?

@StefH commented on GitHub (Jun 28, 2025): @pavlo-khomiak-philips I cannot see which package uses this one. Do you have more details?
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/WireMock.Net#644