Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update the System.Formats.Asn1 package for Az.CodeSigning module #25665

Merged
merged 2 commits into from
Jul 28, 2024

Conversation

Jaxelr
Copy link
Member

@Jaxelr Jaxelr commented Jul 27, 2024

Description

This PR adds a dependency on the package System.Formats.Asn1 since the default transitive dependency of the System.Security.Cryptography.Pkcs package contains a vvulnerability reported on the CVE-2024-38095

cc: @isra-fel

Mandatory Checklist

  • SHOULD update ChangeLog.md file(s) appropriately
    • For SDK-based development mode, update src/{{SERVICE}}/{{SERVICE}}/ChangeLog.md.
      • A snippet outlining the change(s) made in the PR should be written under the ## Upcoming Release header in the past tense.
    • For autorest-based development mode, include the changelog in the PR description.
    • Should not change ChangeLog.md if no new release is required, such as fixing test case only.
  • SHOULD regenerate markdown help files if there is cmdlet API change. Instruction
  • SHOULD have proper test coverage for changes in pull request.
  • SHOULD NOT adjust version of module manually in pull request

Copy link

azure-client-tools-bot-prd bot commented Jul 27, 2024

️✔️Az.Accounts
️✔️Build
️✔️PowerShell Core - Windows
️✔️Windows PowerShell - Windows
⚠️Az.CodeSigning
️✔️Build
️✔️PowerShell Core - Windows
️✔️Windows PowerShell - Windows
️✔️File Change Check
️✔️PowerShell Core - Windows
️✔️Windows PowerShell - Windows
⚠️Test
⚠️ - Linux
Type Title Current Coverage Description
⚠️ Test Coverage Less Than 50% 0.00 % Test coverage for the module cannot be lower than 50%.
⚠️ - MacOS
Type Title Current Coverage Description
⚠️ Test Coverage Less Than 50% 0.00% Test coverage for the module cannot be lower than 50%.
⚠️PowerShell Core - Windows
Type Title Current Coverage Description
⚠️ Test Coverage Less Than 50% 0.00% Test coverage for the module cannot be lower than 50%.
⚠️Windows PowerShell - Windows
Type Title Current Coverage Description
⚠️ Test Coverage Less Than 50% 0.00% Test coverage for the module cannot be lower than 50%.

@VeryEarly
Copy link
Contributor

/azp run azure-powershell - security-tools

Copy link
Contributor

Azure Pipelines successfully started running 1 pipeline(s).

@VeryEarly VeryEarly self-assigned this Jul 28, 2024
@VeryEarly VeryEarly merged commit 445805b into Azure:main Jul 28, 2024
12 checks passed
github-actions bot pushed a commit that referenced this pull request Jul 28, 2024
)

* Update the System.Formats.Asn1 package

This fix addresses CVE-2024-38095

* update changelog.md
@Jaxelr Jaxelr deleted the az.codesigning/update-dependency branch July 28, 2024 13:51
VeryEarly added a commit that referenced this pull request Aug 6, 2024
) (#25749)

* Update the System.Formats.Asn1 package

This fix addresses CVE-2024-38095

* update changelog.md

Co-authored-by: Jaxel Rojas <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants