Skip to content

Package 'Newtonsoft.Json' 9.0.1 has a known moderate severity (coverlet.core) #1505

@Bertk

Description

@Bertk

Project coverlet.core uses vulnerable Package 'Newtonsoft.Json 9.0.1'. This assembly is also added coverlet Nuget packages.

image

The version is defined in Directory.Build.targets with comment "Do not upgrade".

    <!-- Do not upgrade this version or we won't support old SDK -->
    <PackageReference Update="Newtonsoft.Json" Version="9.0.1" />
    <PackageReference Update="NuGet.Packaging" Version="5.4.0" />
    <PackageReference Update="ReportGenerator.Core" Version="4.6.0" />

When will the Newtonsoft.Json package version be upgraded to V13.0.3?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions