Skip to content

Snyk upgrade 0fad199008a8f67dff6f753d09c3bfe5#1466

Open
Codes-Exe wants to merge 889 commits intomicrosoft:anikam-pbkdf2from
Codes-Exe:snyk-upgrade-0fad199008a8f67dff6f753d09c3bfe5
Open

Snyk upgrade 0fad199008a8f67dff6f753d09c3bfe5#1466
Codes-Exe wants to merge 889 commits intomicrosoft:anikam-pbkdf2from
Codes-Exe:snyk-upgrade-0fad199008a8f67dff6f753d09c3bfe5

Conversation

@Codes-Exe
Copy link

No description provided.

Codes-Exe and others added 30 commits May 23, 2022 04:39
…s/features/json/reactjs/dotnet-comments-app/Microsoft.AspNetCore.Mvc-1.0.4

Bump Microsoft.AspNetCore.Mvc from 1.0.3 to 1.0.4 in /samples/features/json/reactjs/dotnet-comments-app
…s/features/json/todo-app/dotnet-rest-api/Microsoft.AspNetCore.Mvc-1.0.4

Bump Microsoft.AspNetCore.Mvc from 1.0.3 to 1.0.4 in /samples/features/json/todo-app/dotnet-rest-api
Bumps Microsoft.AspNetCore.Mvc from 1.0.3 to 1.0.4.

---
updated-dependencies:
- dependency-name: Microsoft.AspNetCore.Mvc
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…mples/demos/azure-sql-edge-demos/Wind-Turbine-Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp/node-sass-7.0.0

Bump node-sass from 4.13.0 to 7.0.0 in /samples/demos/azure-sql-edge-demos/Wind Turbine Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp
…mples/demos/azure-sql-edge-demos/Wind-Turbine-Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp/url-parse-1.5.10

Bump url-parse from 1.4.7 to 1.5.10 in /samples/demos/azure-sql-edge-demos/Wind Turbine Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp
…mples/demos/azure-sql-edge-demos/Wind-Turbine-Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp/lodash-4.17.21

Bump lodash from 4.17.15 to 4.17.21 in /samples/demos/azure-sql-edge-demos/Wind Turbine Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp
…mples/demos/azure-sql-edge-demos/Wind-Turbine-Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp/follow-redirects-1.14.9

Bump follow-redirects from 1.9.0 to 1.14.9 in /samples/demos/azure-sql-edge-demos/Wind Turbine Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp
…mples/demos/azure-sql-edge-demos/Wind-Turbine-Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp/async-2.6.4

Bump async from 2.6.3 to 2.6.4 in /samples/demos/azure-sql-edge-demos/Wind Turbine Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp
…eatures/json/todo-app/dotnet-rest-api/Microsoft.AspNetCore.Mvc-1.0.4

Bump Microsoft.AspNetCore.Mvc from 1.0.3 to 1.0.4 in /samples/features/json/todo-app/dotnet-rest-api
…eatures/json/reactjs/dotnet-comments-app/Microsoft.AspNetCore.Mvc-1.0.4

Bump Microsoft.AspNetCore.Mvc from 1.0.3 to 1.0.4 in /samples/features/json/reactjs/dotnet-comments-app
…ures/json/angularjs/dotnet-tour-of-heroes/Microsoft.AspNetCore.Mvc-1.0.4

Bump Microsoft.AspNetCore.Mvc from 1.0.3 to 1.0.4 in /samples/features/json/angularjs/dotnet-tour-of-heroes
Bumps Microsoft.AspNetCore.Mvc from 1.0.3 to 1.0.4.

---
updated-dependencies:
- dependency-name: Microsoft.AspNetCore.Mvc
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [eventsource](https://github.com/EventSource/eventsource) from 1.0.7 to 1.1.1.
- [Release notes](https://github.com/EventSource/eventsource/releases)
- [Changelog](https://github.com/EventSource/eventsource/blob/master/HISTORY.md)
- [Commits](EventSource/eventsource@v1.0.7...v1.1.1)

---
updated-dependencies:
- dependency-name: eventsource
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [eventsource](https://github.com/EventSource/eventsource) from 1.0.7 to 1.1.1.
- [Release notes](https://github.com/EventSource/eventsource/releases)
- [Changelog](https://github.com/EventSource/eventsource/blob/master/HISTORY.md)
- [Commits](EventSource/eventsource@v1.0.7...v1.1.1)

---
updated-dependencies:
- dependency-name: eventsource
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [Newtonsoft.Json](https://github.com/JamesNK/Newtonsoft.Json) from 11.0.2 to 13.0.1.
- [Release notes](https://github.com/JamesNK/Newtonsoft.Json/releases)
- [Commits](JamesNK/Newtonsoft.Json@11.0.2...13.0.1)

---
updated-dependencies:
- dependency-name: Newtonsoft.Json
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [Newtonsoft.Json](https://github.com/JamesNK/Newtonsoft.Json) from 6.0.4 to 13.0.1.
- [Release notes](https://github.com/JamesNK/Newtonsoft.Json/releases)
- [Commits](JamesNK/Newtonsoft.Json@6.0.4...13.0.1)

---
updated-dependencies:
- dependency-name: Newtonsoft.Json
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [Newtonsoft.Json](https://github.com/JamesNK/Newtonsoft.Json) from 6.0.4 to 13.0.1.
- [Release notes](https://github.com/JamesNK/Newtonsoft.Json/releases)
- [Commits](JamesNK/Newtonsoft.Json@6.0.4...13.0.1)

---
updated-dependencies:
- dependency-name: Newtonsoft.Json
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [Newtonsoft.Json](https://github.com/JamesNK/Newtonsoft.Json) from 6.0.4 to 13.0.1.
- [Release notes](https://github.com/JamesNK/Newtonsoft.Json/releases)
- [Commits](JamesNK/Newtonsoft.Json@6.0.4...13.0.1)

---
updated-dependencies:
- dependency-name: Newtonsoft.Json
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [Newtonsoft.Json](https://github.com/JamesNK/Newtonsoft.Json) from 11.0.2 to 13.0.1.
- [Release notes](https://github.com/JamesNK/Newtonsoft.Json/releases)
- [Commits](JamesNK/Newtonsoft.Json@11.0.2...13.0.1)

---
updated-dependencies:
- dependency-name: Newtonsoft.Json
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [Newtonsoft.Json](https://github.com/JamesNK/Newtonsoft.Json) from 6.0.4 to 13.0.1.
- [Release notes](https://github.com/JamesNK/Newtonsoft.Json/releases)
- [Commits](JamesNK/Newtonsoft.Json@6.0.4...13.0.1)

---
updated-dependencies:
- dependency-name: Newtonsoft.Json
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…demos/azure-sql-edge-demos/Wind-Turbine-Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp/eventsource-1.1.1

Bump eventsource from 1.0.7 to 1.1.1 in /samples/demos/azure-sql-edge-demos/Wind Turbine Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp
…es/wide-world-importers/wwi-app/Newtonsoft.Json-13.0.1

Bump Newtonsoft.Json from 11.0.2 to 13.0.1 in /samples/databases/wide-world-importers/wwi-app
…s/security/contoso-clinic/src/ContosoClinic/Newtonsoft.Json-13.0.1

Bump Newtonsoft.Json from 6.0.4 to 13.0.1 in /samples/features/security/contoso-clinic/src/ContosoClinic
…azure-sql-db-elastic-pools-custom-dashboard/Contoso-ShopKeeper/MonitoringWebApp/Newtonsoft.Json-13.0.1

Bump Newtonsoft.Json from 6.0.4 to 13.0.1 in /samples/manage/azure-sql-db-elastic-pools-custom-dashboard/Contoso ShopKeeper/MonitoringWebApp
…res/json/angularjs/dotnet-tour-of-heroes/Microsoft.AspNetCore.Mvc-1.0.4

Bump Microsoft.AspNetCore.Mvc from 1.0.3 to 1.0.4 in /samples/features/json/angularjs/dotnet-tour-of-heroes
…s/demos/azure-sql-edge-demos/Wind-Turbine-Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp/eventsource-1.1.1

Bump eventsource from 1.0.7 to 1.1.1 in /samples/demos/azure-sql-edge-demos/Wind Turbine Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp
…ge/azure-sql-db-elastic-pools-custom-dashboard/Contoso-ShopKeeper/MonitoringWebApp/Newtonsoft.Json-13.0.1

Bump Newtonsoft.Json from 6.0.4 to 13.0.1 in /samples/manage/azure-sql-db-elastic-pools-custom-dashboard/Contoso ShopKeeper/MonitoringWebApp
…ures/security/contoso-clinic/src/ContosoClinic/Newtonsoft.Json-13.0.1

Bump Newtonsoft.Json from 6.0.4 to 13.0.1 in /samples/features/security/contoso-clinic/src/ContosoClinic
…bases/wide-world-importers/wwi-app/Newtonsoft.Json-13.0.1

Bump Newtonsoft.Json from 11.0.2 to 13.0.1 in /samples/databases/wide-world-importers/wwi-app
dependabot bot and others added 30 commits October 19, 2024 10:33
Bumps [cookie](https://github.com/jshttp/cookie) and [express](https://github.com/expressjs/express). These dependencies needed to be updated together.

Updates `cookie` from 0.6.0 to 0.7.1
- [Release notes](https://github.com/jshttp/cookie/releases)
- [Commits](jshttp/cookie@v0.6.0...v0.7.1)

Updates `express` from 4.21.0 to 4.21.1
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/4.21.1/History.md)
- [Commits](expressjs/express@4.21.0...4.21.1)

---
updated-dependencies:
- dependency-name: cookie
  dependency-type: indirect
- dependency-name: express
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [http-proxy-middleware](https://github.com/chimurai/http-proxy-middleware) from 2.0.6 to 2.0.7.
- [Release notes](https://github.com/chimurai/http-proxy-middleware/releases)
- [Changelog](https://github.com/chimurai/http-proxy-middleware/blob/v2.0.7/CHANGELOG.md)
- [Commits](chimurai/http-proxy-middleware@v2.0.6...v2.0.7)

---
updated-dependencies:
- dependency-name: http-proxy-middleware
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [cross-spawn](https://github.com/moxystudio/node-cross-spawn) from 7.0.3 to 7.0.6.
- [Changelog](https://github.com/moxystudio/node-cross-spawn/blob/master/CHANGELOG.md)
- [Commits](moxystudio/node-cross-spawn@v7.0.3...v7.0.6)

---
updated-dependencies:
- dependency-name: cross-spawn
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…/demos/azure-sql-edge-demos/Wind-Turbine-Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp/multi-9f37c16f8f

Bump cookie and express in /samples/demos/azure-sql-edge-demos/Wind Turbine Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp
…/demos/azure-sql-edge-demos/Wind-Turbine-Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp/http-proxy-middleware-2.0.7

Bump http-proxy-middleware from 2.0.6 to 2.0.7 in /samples/demos/azure-sql-edge-demos/Wind Turbine Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp
…/demos/azure-sql-edge-demos/Wind-Turbine-Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp/cross-spawn-7.0.6

Bump cross-spawn from 7.0.3 to 7.0.6 in /samples/demos/azure-sql-edge-demos/Wind Turbine Demo/webappsrc/SqlDbEdgeDemoWeb/SqlDbEdgeDemo.Web/ClientApp
….Final

Snyk has created this PR to upgrade org.hibernate:hibernate-core from 5.3.20.Final to 5.6.15.Final.

See this package in maven:
org.hibernate:hibernate-core

See this project in Snyk:
https://app.snyk.io/org/codes-exe/project/bed8cea5-fb83-4d3f-8637-62a893201033?utm_source=github&utm_medium=referral&page=upgrade-pr
…4.0.jre8

Snyk has created this PR to upgrade com.microsoft.sqlserver:mssql-jdbc from 6.2.2.jre8 to 6.4.0.jre8.

See this package in maven:
com.microsoft.sqlserver:mssql-jdbc

See this project in Snyk:
https://app.snyk.io/org/codes-exe/project/bed8cea5-fb83-4d3f-8637-62a893201033?utm_source=github&utm_medium=referral&page=upgrade-pr
… vulnerabilities

The following vulnerabilities are fixed by pinning transitive dependencies:
- https://snyk.io/vuln/SNYK-PYTHON-GUNICORN-9510910
- Microsoft.Data.SqlClient to 5.1.3
- System.Linq.Dynamic.Core to 1.6.0

---
updated-dependencies:
- dependency-name: Microsoft.Data.SqlClient
  dependency-version: 5.1.3
  dependency-type: direct:production
- dependency-name: System.Linq.Dynamic.Core
  dependency-version: 1.6.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
- jQuery to 3.5.0
- jQuery.Validation to 1.19.3
- Microsoft.AspNet.Identity.Owin to 2.2.4

---
updated-dependencies:
- dependency-name: jQuery
  dependency-version: 3.5.0
  dependency-type: direct:production
- dependency-name: jQuery.Validation
  dependency-version: 1.19.3
  dependency-type: direct:production
- dependency-name: Microsoft.AspNet.Identity.Owin
  dependency-version: 2.2.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…script/requirements.txt to reduce vulnerabilities

The following vulnerabilities are fixed by pinning transitive dependencies:
- https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-10305723
Bumps the maven group with 1 update in the /samples/tutorials/java/RHEL/SqlServerColumnstoreSample directory: [com.microsoft.sqlserver:mssql-jdbc](https://github.com/Microsoft/mssql-jdbc).
Bumps the maven group with 1 update in the /samples/tutorials/java/RHEL/SqlServerHibernateSample directory: [com.microsoft.sqlserver:mssql-jdbc](https://github.com/Microsoft/mssql-jdbc).
Bumps the maven group with 1 update in the /samples/tutorials/java/RHEL/SqlServerSample directory: [com.microsoft.sqlserver:mssql-jdbc](https://github.com/Microsoft/mssql-jdbc).
Bumps the maven group with 1 update in the /samples/tutorials/java/Ubuntu/SqlServerColumnstoreSample directory: [com.microsoft.sqlserver:mssql-jdbc](https://github.com/Microsoft/mssql-jdbc).
Bumps the maven group with 1 update in the /samples/tutorials/java/Ubuntu/SqlServerHibernateSample directory: [com.microsoft.sqlserver:mssql-jdbc](https://github.com/Microsoft/mssql-jdbc).
Bumps the maven group with 1 update in the /samples/tutorials/java/Ubuntu/SqlServerSample directory: [com.microsoft.sqlserver:mssql-jdbc](https://github.com/Microsoft/mssql-jdbc).
Bumps the maven group with 1 update in the /samples/tutorials/java/Windows/SqlServerColumnstoreSample directory: [com.microsoft.sqlserver:mssql-jdbc](https://github.com/Microsoft/mssql-jdbc).
Bumps the maven group with 1 update in the /samples/tutorials/java/Windows/SqlServerHibernateSample directory: [com.microsoft.sqlserver:mssql-jdbc](https://github.com/Microsoft/mssql-jdbc).
Bumps the maven group with 1 update in the /samples/tutorials/java/Windows/SqlServerSample directory: [com.microsoft.sqlserver:mssql-jdbc](https://github.com/Microsoft/mssql-jdbc).
Bumps the maven group with 1 update in the /samples/tutorials/java/macOS/SqlServerColumnstoreSample directory: [com.microsoft.sqlserver:mssql-jdbc](https://github.com/Microsoft/mssql-jdbc).


Updates `com.microsoft.sqlserver:mssql-jdbc` from 6.2.2.jre8 to 10.2.4.jre8
- [Release notes](https://github.com/Microsoft/mssql-jdbc/releases)
- [Changelog](https://github.com/microsoft/mssql-jdbc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Microsoft/mssql-jdbc/commits)

Updates `com.microsoft.sqlserver:mssql-jdbc` from 6.2.2.jre8 to 10.2.4.jre8
- [Release notes](https://github.com/Microsoft/mssql-jdbc/releases)
- [Changelog](https://github.com/microsoft/mssql-jdbc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Microsoft/mssql-jdbc/commits)

Updates `com.microsoft.sqlserver:mssql-jdbc` from 6.2.2.jre8 to 10.2.4.jre8
- [Release notes](https://github.com/Microsoft/mssql-jdbc/releases)
- [Changelog](https://github.com/microsoft/mssql-jdbc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Microsoft/mssql-jdbc/commits)

Updates `com.microsoft.sqlserver:mssql-jdbc` from 6.2.2.jre8 to 10.2.4.jre8
- [Release notes](https://github.com/Microsoft/mssql-jdbc/releases)
- [Changelog](https://github.com/microsoft/mssql-jdbc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Microsoft/mssql-jdbc/commits)

Updates `com.microsoft.sqlserver:mssql-jdbc` from 6.2.2.jre8 to 10.2.4.jre8
- [Release notes](https://github.com/Microsoft/mssql-jdbc/releases)
- [Changelog](https://github.com/microsoft/mssql-jdbc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Microsoft/mssql-jdbc/commits)

Updates `com.microsoft.sqlserver:mssql-jdbc` from 6.2.2.jre8 to 10.2.4.jre8
- [Release notes](https://github.com/Microsoft/mssql-jdbc/releases)
- [Changelog](https://github.com/microsoft/mssql-jdbc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Microsoft/mssql-jdbc/commits)

Updates `com.microsoft.sqlserver:mssql-jdbc` from 6.2.2.jre8 to 10.2.4.jre8
- [Release notes](https://github.com/Microsoft/mssql-jdbc/releases)
- [Changelog](https://github.com/microsoft/mssql-jdbc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Microsoft/mssql-jdbc/commits)

Updates `com.microsoft.sqlserver:mssql-jdbc` from 6.2.2.jre8 to 10.2.4.jre8
- [Release notes](https://github.com/Microsoft/mssql-jdbc/releases)
- [Changelog](https://github.com/microsoft/mssql-jdbc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Microsoft/mssql-jdbc/commits)

Updates `com.microsoft.sqlserver:mssql-jdbc` from 6.2.2.jre8 to 10.2.4.jre8
- [Release notes](https://github.com/Microsoft/mssql-jdbc/releases)
- [Changelog](https://github.com/microsoft/mssql-jdbc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Microsoft/mssql-jdbc/commits)

Updates `com.microsoft.sqlserver:mssql-jdbc` from 6.2.2.jre8 to 10.2.4.jre8
- [Release notes](https://github.com/Microsoft/mssql-jdbc/releases)
- [Changelog](https://github.com/microsoft/mssql-jdbc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Microsoft/mssql-jdbc/commits)

---
updated-dependencies:
- dependency-name: com.microsoft.sqlserver:mssql-jdbc
  dependency-version: 10.2.4.jre8
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.microsoft.sqlserver:mssql-jdbc
  dependency-version: 10.2.4.jre8
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.microsoft.sqlserver:mssql-jdbc
  dependency-version: 10.2.4.jre8
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.microsoft.sqlserver:mssql-jdbc
  dependency-version: 10.2.4.jre8
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.microsoft.sqlserver:mssql-jdbc
  dependency-version: 10.2.4.jre8
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.microsoft.sqlserver:mssql-jdbc
  dependency-version: 10.2.4.jre8
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.microsoft.sqlserver:mssql-jdbc
  dependency-version: 10.2.4.jre8
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.microsoft.sqlserver:mssql-jdbc
  dependency-version: 10.2.4.jre8
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.microsoft.sqlserver:mssql-jdbc
  dependency-version: 10.2.4.jre8
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.microsoft.sqlserver:mssql-jdbc
  dependency-version: 10.2.4.jre8
  dependency-type: direct:production
  dependency-group: maven
...

Signed-off-by: dependabot[bot] <support@github.com>
… to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JAVA-COMMICROSOFTSQLSERVER-13821835
…o reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JAVA-COMMICROSOFTSQLSERVER-13821835
…on to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-ANGULARCOMPILER-14157154
…ae8b02b4cf2c33

[Snyk] Upgrade org.hibernate:hibernate-core from 5.3.20.Final to 5.6.15.Final
…es/security/always-encrypted-with-secure-enclaves/source/ContosoHR/multi-d99aef75a6

Update Microsoft.Data.SqlClient to 5.1.3; System.Linq.Dynamic.Core to 1.6.0
…/azure-sql-db-elastic-pools-custom-dashboard/Contoso-ShopKeeper/MonitoringWebApp/multi-155991564b

Update jQuery and 2 other dependencies
…7fae0069d0

[Snyk] Security upgrade requests from 2.31.0 to 2.32.4
…8337fdad34

[Snyk] Security upgrade @angular/compiler from 2.1.2 to 19.2.17
…ac508fb78f

[Snyk] Security upgrade gunicorn from 19.6.0 to 23.0.0
…eb29f367b6

[Snyk] Security upgrade com.microsoft.sqlserver:mssql-jdbc from 6.2.2.jre8 to 10.2.4.jre8
…261559f11b

[Snyk] Security upgrade com.microsoft.sqlserver:mssql-jdbc from 6.2.2.jre8 to 10.2.4.jre8
…584c79f681

[Snyk] Security upgrade com.microsoft.sqlserver:mssql-jdbc from 6.2.2.jre8 to 10.2.4.jre8
… vulnerabilities

The following vulnerabilities are fixed by pinning transitive dependencies:
- https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899
…65a39d39f60

[Snyk] Security upgrade zipp from 3.15.0 to 3.19.1
…als/java/RHEL/SqlServerColumnstoreSample/maven-307b624702

Bump the maven group across 10 directories with 1 update
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants