You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PuppeteerSharp currently introduces an RCE vulnerability with System.Text.Encodings.Web@4.0.2.0 through a sample project here, and it's throwing off Snyk scanning thinking that's an actual vulnerability... Wondering if that could be upgraded to match a fixed version as listed on that Snyk link?
Complete minimal example reproducing the issue
Nothing to reproduce, this is just a vulnerability that's throwing off scanners.
Expected behavior: Vulnerable package System.Text.Encodings.Web@4.0.2.0 throws off scanner
[What you expect to happen]
Actual behavior: Scanner not to go off with that vulnerability
[What actually happens]
Versions
Which version of PuppeteerSharp are you using? 6.2.0
Which .NET runtime and version are you targeting? .NET framework 4.6.1 and .NET Standard 2.0
Additional Information
N/A
The text was updated successfully, but these errors were encountered:
Description
PuppeteerSharp currently introduces an RCE vulnerability with System.Text.Encodings.Web@4.0.2.0 through a sample project here, and it's throwing off Snyk scanning thinking that's an actual vulnerability... Wondering if that could be upgraded to match a fixed version as listed on that Snyk link?
Complete minimal example reproducing the issue
Expected behavior: Vulnerable package System.Text.Encodings.Web@4.0.2.0 throws off scanner
[What you expect to happen]
Actual behavior: Scanner not to go off with that vulnerability
[What actually happens]
Versions
Additional Information
N/A
The text was updated successfully, but these errors were encountered: