Skip to content
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.

Commit 27386b9

Browse files
committedMay 21, 2025·
NCBC-4026: Upgrade Grpc.Net.Client (and other required)
Motivation ---------- BlackDuck isn’t reporting the vulnerability, but according to OSV - Open Source Vulnerabilities Grpc.Net.CLient 2.5.0.o used in Couchbase.csproj and Couchbase.Stellar.CodeGen.csproj present a vulnerability. Changes ------- - Upgrade Grpc dependencies and other required transitive dependencies Change-Id: Ie2c15fb3fc1800921a848ceaf55182e104756158 Reviewed-on: https://review.couchbase.org/c/couchbase-net-client/+/227979 Tested-by: Build Bot <[email protected]> Reviewed-by: David Kelly <[email protected]>
1 parent 6c18702 commit 27386b9

File tree

1 file changed

+12
-9
lines changed

1 file changed

+12
-9
lines changed
 

‎Directory.Packages.props

Lines changed: 12 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -4,19 +4,22 @@
44
</PropertyGroup>
55
<!-- General dependencies -->
66
<ItemGroup>
7-
<PackageVersion Include="Google.Protobuf" Version="3.25.0" />
8-
<PackageVersion Include="Grpc.Net.Client" Version="2.50.0" />
9-
<PackageVersion Include="Grpc.Net.ClientFactory" Version="2.50.0" />
10-
<PackageVersion Include="Google.Api.CommonProtos" Version="2.13.0" />
11-
<PackageVersion Include="Grpc.Tools" Version="2.51.0" />
7+
<PackageVersion Include="Google.Protobuf" Version="3.31.0" />
8+
<PackageVersion Include="Grpc.Net.Client" Version="2.71.0" />
9+
<PackageVersion Include="Grpc.Net.ClientFactory" Version="2.71.0" />
10+
<PackageVersion Include="Google.Api.CommonProtos" Version="2.16.0" />
11+
<PackageVersion Include="Grpc.Tools" Version="2.72.0">
12+
<PrivateAssets>all</PrivateAssets>
13+
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
14+
</PackageVersion>
1215
<PackageVersion Include="DnsClient" Version="1.8.0" />
1316
<PackageVersion Include="Microsoft.Bcl.TimeProvider" Version="8.0.1" />
1417
<PackageVersion Include="Microsoft.Extensions.Configuration" Version="3.1.21" />
1518
<PackageVersion Include="Microsoft.Extensions.Configuration.Binder" Version="3.1.21" />
1619
<PackageVersion Include="Microsoft.Extensions.DependencyInjection.Abstractions" Version="8.0.0" />
1720
<PackageVersion Include="Microsoft.Extensions.Logging.Abstractions" Version="6.0.1" />
1821
<PackageVersion Include="Microsoft.Extensions.ObjectPool" Version="6.0.0" />
19-
<PackageVersion Include="Microsoft.Extensions.Options" Version="3.1.21" />
22+
<PackageVersion Include="Microsoft.Extensions.Options" Version="6.0.0" />
2023
<PackageVersion Include="Newtonsoft.Json" Version="13.0.3" />
2124
<PackageVersion Include="OpenTelemetry" Version="1.2.0" />
2225
<PackageVersion Include="OpenTelemetry.Api" Version="1.2.0" />
@@ -28,8 +31,8 @@
2831
<PackageVersion Include="System.Runtime.CompilerServices.Unsafe" Version="6.1.0" />
2932
<PackageVersion Include="System.Text.Json" Version="8.0.5" />
3033
<PackageVersion Include="System.Threading.Channels" Version="5.0.0" />
31-
<PackageVersion Include="System.Threading.Tasks.Dataflow" Version="5.0.0" />
32-
<PackageVersion Include="System.Diagnostics.DiagnosticSource" Version="6.0.0" />
34+
<PackageVersion Include="System.Threading.Tasks.Dataflow" Version="6.0.0" />
35+
<PackageVersion Include="System.Diagnostics.DiagnosticSource" Version="6.0.1" />
3336
</ItemGroup>
3437
<!-- Dependencies only allowed for .NET Standard 2.0 -->
3538
<ItemGroup Condition=" '$(TargetFramework)' == 'netstandard2.0' ">
@@ -60,4 +63,4 @@
6063
<PackageVersion Include="Xunit.SkippableFact" Version="1.4.13" />
6164
<PackageVersion Include="coverlet.collector" Version="3.1.0" />
6265
</ItemGroup>
63-
</Project>
66+
</Project>

0 commit comments

Comments
 (0)
Please sign in to comment.