PdfSharpCore has an implicitly referenced package (SixLabors.ImageSharp) which has five CVEsΒ #462
Open
Description
I currently have PdfSharpCore version 1.3.65, and Docker Scout is detecting two CVEs relating to a transitively referenced package ImageSharp version 1.0.4.0.
The CVEs: CVE-2024-27929, CVE-2024-41131, CVE-2024-32035, CVE-2024-32036, CVE-2024-41132
I am unable to explicitly install the updated ImageSharp package due to the commercial licence it has, however transitive references are allowed according to ImageSharp's licence.
Can you please update the ImageSharp dependency to the latest version?
Metadata
Assignees
Labels
No labels