Skip to content

Commit

Permalink
Merge pull request microsoft#33 from microsoft/rido/fix-vuln-pkgs
Browse files Browse the repository at this point in the history
update to latest Cosmos package, and referece Newtonsoft in AdaptiveCardActions sample.
  • Loading branch information
rido-min authored Jan 15, 2025
2 parents 1b7bf57 + 04a3b4b commit bc1d648
Show file tree
Hide file tree
Showing 3 changed files with 84 additions and 85 deletions.
164 changes: 82 additions & 82 deletions Directory.Packages.props
Original file line number Diff line number Diff line change
@@ -1,87 +1,87 @@
<Project>
<!-- See: https://docs.microsoft.com/en-us/visualstudio/msbuild/customize-your-build?view=vs-2019#directorybuildprops-and-directorybuildtargets -->
<PropertyGroup>
<!-- Not enabled by default for the repo. -->
<ManagePackageVersionsCentrally>true</ManagePackageVersionsCentrally>
<!-- To avoid NU1507 we must disable library packs from getting added by the SDK.
<Project>
<!-- See: https://docs.microsoft.com/en-us/visualstudio/msbuild/customize-your-build?view=vs-2019#directorybuildprops-and-directorybuildtargets -->
<PropertyGroup>
<!-- Not enabled by default for the repo. -->
<ManagePackageVersionsCentrally>true</ManagePackageVersionsCentrally>
<!-- To avoid NU1507 we must disable library packs from getting added by the SDK.
Error:
The project E:\repos\msazure\One\PowerPlatform-ISVEx-ToolsCore\src\cli\Analyzers\bolt.Analyzers\bolt.Analyzers\bolt.Analyzers.csproj is using CentralPackageVersionManagement, a NuGet preview feature.
E:\repos\msazure\One\PowerPlatform-ISVEx-ToolsCore\src\cli\Analyzers\bolt.Analyzers\bolt.Analyzers\bolt.Analyzers.csproj : warning NU1507: There are 2 package sources defined in your configuration. When using central package management, please map your package sources with package source mapping (https://aka.ms/nuget-package-source-mapping) or specify a single package source. The following sources are defined: https://pkgs.dev.azure.com/msazure/One/_packaging/CAP_ISVExp_Tools_Upstream/nuget/v3/index.json, C:\Program Files\dotnet\library-packs
The 'library-packs' source is added by the SDK.
-->
<DisableImplicitLibraryPacksFolder>true</DisableImplicitLibraryPacksFolder>
</PropertyGroup>
<PropertyGroup>
<Microsoft_Extentions_PkgVer>8.0.0</Microsoft_Extentions_PkgVer>
<Microsoft_AspNetCore_PkgVer>8.0.11</Microsoft_AspNetCore_PkgVer>
</PropertyGroup>
<ItemGroup>
<PackageVersion Include="Microsoft.IdentityModel.Tokens" Version="8.1.2" />
<PackageVersion Include="Nerdbank.GitVersioning" Version="3.6.146" />
<PackageVersion Include="AdaptiveCards.Rendering.Html" Version="2.7.3" />
<PackageVersion Include="Azure.Identity" Version="1.12.1" />
<PackageVersion Include="Azure.Core" Version="1.43.0" />
<PackageVersion Include="Microsoft.Identity.Client" Version="4.64.1" />
<PackageVersion Include="Microsoft.Identity.Client.Extensions.Msal" Version="4.65.0" />
<PackageVersion Include="Microsoft.IdentityModel.Abstractions" Version="8.1.2" />
<PackageVersion Include="Microsoft.IdentityModel.LoggingExtensions" Version="8.1.2" />
<PackageVersion Include="Microsoft.IdentityModel.Validators" Version="8.1.2" />
<PackageVersion Include="Microsoft.IdentityModel.Protocols.OpenIdConnect" Version="8.1.2" />
<PackageVersion Include="System.IdentityModel.Tokens.Jwt" Version="8.0.1" />
<PackageVersion Include="Azure.Security.KeyVault.Certificates" Version="4.6.0" />
<PackageVersion Include="Microsoft.Azure.AutoRest.CSharp" Version="3.0.0-beta.20231020.1"/>
<PackageVersion Include="Microsoft.Extensions.Logging.AzureAppServices" Version="8.0.7" />
<PackageVersion Include="Microsoft.Extensions.Hosting" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Microsoft.Extensions.DependencyInjection" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Microsoft.Extensions.Logging" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Microsoft.Extensions.Configuration" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Microsoft.Extensions.Configuration.Binder" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Microsoft.Extensions.Configuration.Json" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Microsoft.Extensions.Logging.Console" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Microsoft.Extensions.Http" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="System.Text.Json" Version="8.0.5" />
<PackageVersion Include="System.Configuration.ConfigurationManager" Version="8.0.0" />
<!-- ASP.net Core support -->
<PackageVersion Include="Microsoft.AspNetCore.Hosting.Abstractions" Version="$(Microsoft_AspNetCore_PkgVer)" />
<PackageVersion Include="Microsoft.AspNetCore.Authentication.JwtBearer" Version="$(Microsoft_AspNetCore_PkgVer)" />
<PackageVersion Include="Microsoft.AspNetCore.Mvc.Formatters.Json" Version="$(Microsoft_AspNetCore_PkgVer)" />
<PackageVersion Include="Microsoft.AspNetCore.Mvc.Core" Version="$(Microsoft_AspNetCore_PkgVer)" />
<PackageVersion Include="Microsoft.AspNetCore.Http" Version="$(Microsoft_AspNetCore_PkgVer)" />
<!-- Test nuget packages -->
<PackageVersion Include="Microsoft.NET.Test.Sdk" Version="17.11.0" />
<PackageVersion Include="xunit" Version="2.9.0" />
<PackageVersion Include="xunit.runner.visualstudio" Version="2.8.2" />
<PackageVersion Include="coverlet.collector" Version="1.2.0" />
<PackageVersion Include="Moq" Version="4.20.70" />
<PackageVersion Include="Jint" Version="4.0.0" />
<PackageVersion Include="Microsoft.CodeAnalysis.CSharp.Scripting" Version="4.10.0" />
<PackageVersion Include="Microsoft.Recognizers.Text.DataTypes.TimexExpression" Version="1.3.2" />
<PackageVersion Include="xunit.extensibility.core" Version="2.9.0" />
<!-- Bot Framework -->
<PackageVersion Include="Microsoft.ApplicationInsights" Version="2.22.0" />
<PackageVersion Include="Microsoft.Bcl.AsyncInterfaces" Version="8.0.0" />
<PackageVersion Include="Microsoft.Azure.Cosmos" Version="3.43.1" />
<PackageVersion Include="Microsoft.Azure.Storage.Blob" Version="9.4.2" />
<PackageVersion Include="System.Threading.Tasks.Extensions" Version="4.5.4" />
<PackageVersion Include="Azure.Storage.Blobs" Version="12.22.2" />
<PackageVersion Include="Azure.Storage.Queues" Version="12.20.0" />
<PackageVersion Include="Microsoft.Recognizers.Text.Choice" Version="1.3.2" />
<PackageVersion Include="Microsoft.Recognizers.Text.DateTime" Version="1.3.2" />
<PackageVersion Include="Microsoft.Extensions.Logging.Debug" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Newtonsoft.Json" Version="13.0.3" />
<PackageVersion Include="Microsoft.CSharp" Version="4.7.0" />
<PackageVersion Include="AdaptiveExpressions" Version="4.22.7" />
<!-- Bot Framework Sample Migration -->
<PackageVersion Include="Microsoft.AspNetCore.Mvc.NewtonsoftJson" Version="$(Microsoft_Extentions_PkgVer)" />
<!-- Teams samples -->
<PackageVersion Include="AdaptiveCards" Version="3.1.0" />
<PackageVersion Include="AdaptiveCards.Templating" Version="2.0.3" />
<PackageVersion Include="Microsoft.Graph" Version="4.47.0" />
<PackageVersion Include="Microsoft.Graph.Core" Version="2.0.14" />
<!-- Semantic Kernel Samples -->
<PackageVersion Include="Microsoft.SemanticKernel.Agents.Core" Version="1.29.0-alpha" />
<PackageVersion Include="Microsoft.SemanticKernel.Agents.OpenAI" Version="1.29.0-alpha" />
<PackageVersion Include="Microsoft.SemanticKernel.Connectors.AzureOpenAI" Version="1.29.0" />
<PackageVersion Include="Microsoft.SemanticKernel.Connectors.OpenAI" Version="1.29.0" />
</ItemGroup>
-->
<DisableImplicitLibraryPacksFolder>true</DisableImplicitLibraryPacksFolder>
</PropertyGroup>
<PropertyGroup>
<Microsoft_Extentions_PkgVer>8.0.0</Microsoft_Extentions_PkgVer>
<Microsoft_AspNetCore_PkgVer>8.0.11</Microsoft_AspNetCore_PkgVer>
</PropertyGroup>
<ItemGroup>
<PackageVersion Include="Microsoft.IdentityModel.Tokens" Version="8.1.2" />
<PackageVersion Include="Nerdbank.GitVersioning" Version="3.6.146" />
<PackageVersion Include="AdaptiveCards.Rendering.Html" Version="2.7.3" />
<PackageVersion Include="Azure.Identity" Version="1.12.1" />
<PackageVersion Include="Azure.Core" Version="1.43.0" />
<PackageVersion Include="Microsoft.Identity.Client" Version="4.64.1" />
<PackageVersion Include="Microsoft.Identity.Client.Extensions.Msal" Version="4.65.0" />
<PackageVersion Include="Microsoft.IdentityModel.Abstractions" Version="8.1.2" />
<PackageVersion Include="Microsoft.IdentityModel.LoggingExtensions" Version="8.1.2" />
<PackageVersion Include="Microsoft.IdentityModel.Validators" Version="8.1.2" />
<PackageVersion Include="Microsoft.IdentityModel.Protocols.OpenIdConnect" Version="8.1.2" />
<PackageVersion Include="System.IdentityModel.Tokens.Jwt" Version="8.0.1" />
<PackageVersion Include="Azure.Security.KeyVault.Certificates" Version="4.6.0" />
<PackageVersion Include="Microsoft.Azure.AutoRest.CSharp" Version="3.0.0-beta.20231020.1" />
<PackageVersion Include="Microsoft.Extensions.Logging.AzureAppServices" Version="8.0.7" />
<PackageVersion Include="Microsoft.Extensions.Hosting" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Microsoft.Extensions.DependencyInjection" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Microsoft.Extensions.Logging" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Microsoft.Extensions.Configuration" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Microsoft.Extensions.Configuration.Binder" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Microsoft.Extensions.Configuration.Json" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Microsoft.Extensions.Logging.Console" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Microsoft.Extensions.Http" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="System.Text.Json" Version="8.0.5" />
<PackageVersion Include="System.Configuration.ConfigurationManager" Version="8.0.0" />
<!-- ASP.net Core support -->
<PackageVersion Include="Microsoft.AspNetCore.Hosting.Abstractions" Version="$(Microsoft_AspNetCore_PkgVer)" />
<PackageVersion Include="Microsoft.AspNetCore.Authentication.JwtBearer" Version="$(Microsoft_AspNetCore_PkgVer)" />
<PackageVersion Include="Microsoft.AspNetCore.Mvc.Formatters.Json" Version="$(Microsoft_AspNetCore_PkgVer)" />
<PackageVersion Include="Microsoft.AspNetCore.Mvc.Core" Version="$(Microsoft_AspNetCore_PkgVer)" />
<PackageVersion Include="Microsoft.AspNetCore.Http" Version="$(Microsoft_AspNetCore_PkgVer)" />
<!-- Test nuget packages -->
<PackageVersion Include="Microsoft.NET.Test.Sdk" Version="17.11.0" />
<PackageVersion Include="xunit" Version="2.9.0" />
<PackageVersion Include="xunit.runner.visualstudio" Version="2.8.2" />
<PackageVersion Include="coverlet.collector" Version="1.2.0" />
<PackageVersion Include="Moq" Version="4.20.70" />
<PackageVersion Include="Jint" Version="4.0.0" />
<PackageVersion Include="Microsoft.CodeAnalysis.CSharp.Scripting" Version="4.10.0" />
<PackageVersion Include="Microsoft.Recognizers.Text.DataTypes.TimexExpression" Version="1.3.2" />
<PackageVersion Include="xunit.extensibility.core" Version="2.9.0" />
<!-- Bot Framework -->
<PackageVersion Include="Microsoft.ApplicationInsights" Version="2.22.0" />
<PackageVersion Include="Microsoft.Bcl.AsyncInterfaces" Version="8.0.0" />
<PackageVersion Include="Microsoft.Azure.Cosmos" Version="3.46.1" />
<PackageVersion Include="Microsoft.Azure.Storage.Blob" Version="9.4.2" />
<PackageVersion Include="System.Threading.Tasks.Extensions" Version="4.5.4" />
<PackageVersion Include="Azure.Storage.Blobs" Version="12.22.2" />
<PackageVersion Include="Azure.Storage.Queues" Version="12.20.0" />
<PackageVersion Include="Microsoft.Recognizers.Text.Choice" Version="1.3.2" />
<PackageVersion Include="Microsoft.Recognizers.Text.DateTime" Version="1.3.2" />
<PackageVersion Include="Microsoft.Extensions.Logging.Debug" Version="$(Microsoft_Extentions_PkgVer)" />
<PackageVersion Include="Newtonsoft.Json" Version="13.0.3" />
<PackageVersion Include="Microsoft.CSharp" Version="4.7.0" />
<PackageVersion Include="AdaptiveExpressions" Version="4.22.7" />
<!-- Bot Framework Sample Migration -->
<PackageVersion Include="Microsoft.AspNetCore.Mvc.NewtonsoftJson" Version="$(Microsoft_Extentions_PkgVer)" />
<!-- Teams samples -->
<PackageVersion Include="AdaptiveCards" Version="3.1.0" />
<PackageVersion Include="AdaptiveCards.Templating" Version="2.0.3" />
<PackageVersion Include="Microsoft.Graph" Version="4.47.0" />
<PackageVersion Include="Microsoft.Graph.Core" Version="2.0.14" />
<!-- Semantic Kernel Samples -->
<PackageVersion Include="Microsoft.SemanticKernel.Agents.Core" Version="1.29.0-alpha" />
<PackageVersion Include="Microsoft.SemanticKernel.Agents.OpenAI" Version="1.29.0-alpha" />
<PackageVersion Include="Microsoft.SemanticKernel.Connectors.AzureOpenAI" Version="1.29.0" />
<PackageVersion Include="Microsoft.SemanticKernel.Connectors.OpenAI" Version="1.29.0" />
</ItemGroup>
</Project>
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@

<!-- Force newer NewtonSoft because Azure.Cosmos is using one that alerts -->
<PackageReference Include="Microsoft.Azure.Cosmos" />
<PackageReference Include="Newtonsoft.Json" />
<PackageReference Include="System.Threading.Tasks.Extensions" />
</ItemGroup>

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,6 @@
<LangVersion>latest</LangVersion>
</PropertyGroup>

<ItemGroup>
</ItemGroup>

<ItemGroup>
<Compile Remove="Images\**" />
<Content Remove="Images\**" />
Expand All @@ -24,6 +21,7 @@
<ItemGroup>
<PackageReference Include="AdaptiveCards.Rendering.Html" />
<PackageReference Include="AdaptiveCards.Templating" />
<PackageReference Include="Newtonsoft.Json" />
</ItemGroup>

<ItemGroup>
Expand Down

0 comments on commit bc1d648

Please sign in to comment.