Skip to content

feat(manifest): socket manifest dotnet + centralized config-name globs (REA-627, REA-628) - #1404

Closed
Jeppe Fredsgaard Blaabjerg (jfblaa) wants to merge 1 commit into
v1.xfrom
jfblaa/rea-627-socket-manifest-dotnet-compute-netnuget-sbom-reachability
Closed

feat(manifest): socket manifest dotnet + centralized config-name globs (REA-627, REA-628)#1404
Jeppe Fredsgaard Blaabjerg (jfblaa) wants to merge 1 commit into
v1.xfrom
jfblaa/rea-627-socket-manifest-dotnet-compute-netnuget-sbom-reachability

feat(manifest): socket manifest dotnet + centralized config-name glob…

430c9b8
Select commit
Loading
Failed to load commit list.
Socket Security Staging / Socket Security Staging: Pull Request Alerts failed Jul 7, 2026 in 2m 30s

Pull Request #1404 Alerts: Complete with warnings

Report Status Message
PR #1404 Alerts ⚠️ Found 6 project alerts

Pull request alerts notify when new issues are detected between the diff of the pull request and it's target branch.

Details

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. It is recommended to resolve "Warn" alerts too. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block Critical
Critical CVE: NuGet Client Security Feature Bypass Vulnerability in nuget nuget.packaging

CVE: GHSA-68w7-72jg-6qpp NuGet Client Security Feature Bypass Vulnerability (CRITICAL)

Affected versions: = 6.7.0, 6.8.0; >= 4.6.0 < 5.11.6; >= 6.0.0 < 6.0.6; >= 6.3.0 < 6.3.4; >= 6.4.0 < 6.4.3; >= 6.6.0 < 6.6.2; >= 6.7.0 < 6.7.1; >= 6.8.0 < 6.8.1

Patched version: 6.0.6

From: src/commands/manifest/scripts/dotnet-tool/socket-facts-dotnet.csprojnuget/nuget.packaging@6.0.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore nuget/nuget.packaging@6.0.0. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
High CVE: NuGet Client Remote Code Execution Vulnerability in nuget nuget.common

CVE: GHSA-6qmf-mmc7-6c2p NuGet Client Remote Code Execution Vulnerability (HIGH)

Affected versions: = 6.5.0, 6.6.0; >= 6.0.0 < 6.0.5; >= 6.2.0 < 6.2.4; >= 6.3.0 < 6.3.3; >= 6.4.0 < 6.4.2; >= 6.5.0 < 6.5.1; >= 6.6.0 < 6.6.1; >= 4.6.0 < 5.11.5

Patched version: 6.0.5

From: src/commands/manifest/scripts/dotnet-tool/socket-facts-dotnet.csprojnuget/nuget.common@6.0.0

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore nuget/nuget.common@6.0.0. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
High CVE: NuGet Client Remote Code Execution Vulnerability in nuget nuget.protocol

CVE: GHSA-6qmf-mmc7-6c2p NuGet Client Remote Code Execution Vulnerability (HIGH)

Affected versions: = 6.5.0, 6.6.0; >= 6.0.0 < 6.0.5; >= 6.2.0 < 6.2.4; >= 6.3.0 < 6.3.3; >= 6.4.0 < 6.4.2; >= 6.5.0 < 6.5.1; >= 6.6.0 < 6.6.1; >= 4.7.0 < 5.11.5

Patched version: 6.0.5

From: src/commands/manifest/scripts/dotnet-tool/socket-facts-dotnet.csprojnuget/nuget.protocol@6.0.0

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore nuget/nuget.protocol@6.0.0. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
High CVE: NuGet Elevation of Privilege Vulnerability in nuget nuget.protocol

CVE: GHSA-g3q9-xf95-8hp5 NuGet Elevation of Privilege Vulnerability (HIGH)

Affected versions: >= 4.6.0 < 4.9.6; >= 5.0.0 < 5.7.3; >= 5.8.0 < 5.9.3; >= 5.10.0 < 5.11.3; >= 6.0.0 < 6.0.3; >= 6.1.0 < 6.2.2; >= 6.3.0 < 6.3.1

Patched version: 6.0.3

From: src/commands/manifest/scripts/dotnet-tool/socket-facts-dotnet.csprojnuget/nuget.protocol@6.0.0

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore nuget/nuget.protocol@6.0.0. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
High CVE: Microsoft Security Advisory CVE-2024-38095 | .NET Denial of Service Vulnerability in nuget system.formats.asn1

CVE: GHSA-447r-wph3-92pm Microsoft Security Advisory CVE-2024-38095 | .NET Denial of Service Vulnerability (HIGH)

Affected versions: >= 5.0.0-preview.7.20364.11 < 6.0.1; >= 7.0.0-preview.1.22076.8 < 8.0.1

Patched version: 6.0.1

From: src/commands/manifest/scripts/dotnet-tool/socket-facts-dotnet.csprojnuget/nuget.packaging@6.0.0nuget/system.formats.asn1@5.0.0

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore nuget/system.formats.asn1@5.0.0. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
High CVE: Microsoft Security Advisory CVE-2024-43485 | .NET Denial of Service Vulnerability in nuget system.text.json

CVE: GHSA-8g4q-xg66-9fp4 Microsoft Security Advisory CVE-2024-43485 | .NET Denial of Service Vulnerability (HIGH)

Affected versions: >= 8.0.0 < 8.0.5; >= 6.0.0 < 6.0.10

Patched version: 6.0.10

From: src/commands/manifest/scripts/dotnet-tool/socket-facts-dotnet.csprojnuget/microsoft.build@17.3.2nuget/system.text.json@6.0.0

ℹ Read more on: This package | This alert | What is a CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known high severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore nuget/system.text.json@6.0.0. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report