From aedb588c60b6fc8c28e7ebcd7330a89d7a1d53f5 Mon Sep 17 00:00:00 2001 From: Scott Blomquist Date: Thu, 30 Mar 2023 13:17:50 -0700 Subject: [PATCH 1/4] Ignore analyzer warnings until OrchardCore updates for net8.0 --- src/OrchardCore.Build/OrchardCore.Commons.props | 2 +- test/OrchardCore.Tests/OrchardCore.Tests.csproj | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/src/OrchardCore.Build/OrchardCore.Commons.props b/src/OrchardCore.Build/OrchardCore.Commons.props index a368baeb54e..7fd116edc25 100644 --- a/src/OrchardCore.Build/OrchardCore.Commons.props +++ b/src/OrchardCore.Build/OrchardCore.Commons.props @@ -8,7 +8,7 @@ preview $(VersionSuffix)-$(BuildNumber) true - 612,618 + 612,618,ASP0019,ASP0023 true $(NoWarn);CS1591 portable diff --git a/test/OrchardCore.Tests/OrchardCore.Tests.csproj b/test/OrchardCore.Tests/OrchardCore.Tests.csproj index 1fb053a61fd..fd48c325f2b 100644 --- a/test/OrchardCore.Tests/OrchardCore.Tests.csproj +++ b/test/OrchardCore.Tests/OrchardCore.Tests.csproj @@ -5,6 +5,7 @@ $(CommonTargetFrameworks) true + ASP0019,ASP0023 From 5cc9ff85ea53ba3d2c6284ad1fcff4f7af2437f6 Mon Sep 17 00:00:00 2001 From: Scott Blomquist Date: Fri, 4 Nov 2022 14:39:59 -0700 Subject: [PATCH 2/4] Constrain System.Drawing version to fix CVE (#5) --- .vscode/settings.json | 3 ++- .../OrchardCore.DataProtection.Azure.csproj | 3 ++- .../OrchardCore.Data.YesSql/OrchardCore.Data.YesSql.csproj | 1 + 3 files changed, 5 insertions(+), 2 deletions(-) diff --git a/.vscode/settings.json b/.vscode/settings.json index 944e8ed31f8..ed9f0ef096f 100644 --- a/.vscode/settings.json +++ b/.vscode/settings.json @@ -1,4 +1,5 @@ // Place your settings in this file to overwrite default and user settings. { - "omnisharp.projectLoadTimeout": 600 + "omnisharp.projectLoadTimeout": 600, + "FSharp.suggestGitignore": false } diff --git a/src/OrchardCore.Modules/OrchardCore.DataProtection.Azure/OrchardCore.DataProtection.Azure.csproj b/src/OrchardCore.Modules/OrchardCore.DataProtection.Azure/OrchardCore.DataProtection.Azure.csproj index 25d4002aa20..e2e963376ed 100644 --- a/src/OrchardCore.Modules/OrchardCore.DataProtection.Azure/OrchardCore.DataProtection.Azure.csproj +++ b/src/OrchardCore.Modules/OrchardCore.DataProtection.Azure/OrchardCore.DataProtection.Azure.csproj @@ -14,7 +14,8 @@ - + + diff --git a/src/OrchardCore/OrchardCore.Data.YesSql/OrchardCore.Data.YesSql.csproj b/src/OrchardCore/OrchardCore.Data.YesSql/OrchardCore.Data.YesSql.csproj index 98fd6bd261b..48a94c3d97a 100644 --- a/src/OrchardCore/OrchardCore.Data.YesSql/OrchardCore.Data.YesSql.csproj +++ b/src/OrchardCore/OrchardCore.Data.YesSql/OrchardCore.Data.YesSql.csproj @@ -23,6 +23,7 @@ + From c9bfe8c9caec597b58885f5bcb97d31f9fc3007c Mon Sep 17 00:00:00 2001 From: Drew Scoggins Date: Mon, 21 Aug 2023 15:42:57 -0700 Subject: [PATCH 3/4] Update System.Drawing dependencies (#7) --- .../OrchardCore.DataProtection.Azure.csproj | 2 +- .../OrchardCore.Data.YesSql/OrchardCore.Data.YesSql.csproj | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/src/OrchardCore.Modules/OrchardCore.DataProtection.Azure/OrchardCore.DataProtection.Azure.csproj b/src/OrchardCore.Modules/OrchardCore.DataProtection.Azure/OrchardCore.DataProtection.Azure.csproj index e2e963376ed..91277f16d36 100644 --- a/src/OrchardCore.Modules/OrchardCore.DataProtection.Azure/OrchardCore.DataProtection.Azure.csproj +++ b/src/OrchardCore.Modules/OrchardCore.DataProtection.Azure/OrchardCore.DataProtection.Azure.csproj @@ -14,7 +14,7 @@ - + diff --git a/src/OrchardCore/OrchardCore.Data.YesSql/OrchardCore.Data.YesSql.csproj b/src/OrchardCore/OrchardCore.Data.YesSql/OrchardCore.Data.YesSql.csproj index 48a94c3d97a..7c6d3e2456a 100644 --- a/src/OrchardCore/OrchardCore.Data.YesSql/OrchardCore.Data.YesSql.csproj +++ b/src/OrchardCore/OrchardCore.Data.YesSql/OrchardCore.Data.YesSql.csproj @@ -23,7 +23,7 @@ - + From 33f460f5dfa93a33ccc95703c0c0a2751409600d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Alexander=20K=C3=B6plinger?= Date: Wed, 8 Nov 2023 18:23:26 +0100 Subject: [PATCH 4/4] Update HtmlSanitizer (#8) The old version has known vulnerabilities. --- src/OrchardCore.Build/Dependencies.props | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/OrchardCore.Build/Dependencies.props b/src/OrchardCore.Build/Dependencies.props index 581c1295d2f..4a184365b6b 100644 --- a/src/OrchardCore.Build/Dependencies.props +++ b/src/OrchardCore.Build/Dependencies.props @@ -25,7 +25,7 @@ - +