From 0122db15f218b20d60b299a11be2d7af44e32c73 Mon Sep 17 00:00:00 2001 From: "Achim H." Date: Tue, 5 May 2026 15:39:28 +0200 Subject: [PATCH] added vulnerable (outdated) package to test Trivy --- MyHelloWorld.Tests/MyHelloWorld.Tests.csproj | 3 ++ .../net8.0/MyHelloWorld.Tests.AssemblyInfo.cs | 2 +- ...yHelloWorld.Tests.AssemblyInfoInputs.cache | 2 +- .../net8.0/MyHelloWorld.Tests.assets.cache | Bin 70082 -> 70205 bytes ...World.Tests.csproj.AssemblyReference.cache | Bin 9240 -> 9240 bytes ...yHelloWorld.Tests.csproj.nuget.dgspec.json | 12 ++++++-- MyHelloWorld.Tests/obj/project.assets.json | 27 +++++++++++++----- MyHelloWorld.Tests/obj/project.nuget.cache | 4 +-- 8 files changed, 37 insertions(+), 13 deletions(-) diff --git a/MyHelloWorld.Tests/MyHelloWorld.Tests.csproj b/MyHelloWorld.Tests/MyHelloWorld.Tests.csproj index 48ef0db..527885e 100644 --- a/MyHelloWorld.Tests/MyHelloWorld.Tests.csproj +++ b/MyHelloWorld.Tests/MyHelloWorld.Tests.csproj @@ -7,6 +7,8 @@ false true + $(NoWarn);NU1901;NU1902;NU1903;NU1904;NU1605 + @@ -15,6 +17,7 @@ + diff --git a/MyHelloWorld.Tests/obj/Debug/net8.0/MyHelloWorld.Tests.AssemblyInfo.cs b/MyHelloWorld.Tests/obj/Debug/net8.0/MyHelloWorld.Tests.AssemblyInfo.cs index 5912f74..97bb600 100644 --- a/MyHelloWorld.Tests/obj/Debug/net8.0/MyHelloWorld.Tests.AssemblyInfo.cs +++ b/MyHelloWorld.Tests/obj/Debug/net8.0/MyHelloWorld.Tests.AssemblyInfo.cs @@ -13,7 +13,7 @@ using System.Reflection; [assembly: System.Reflection.AssemblyCompanyAttribute("MyHelloWorld.Tests")] [assembly: System.Reflection.AssemblyConfigurationAttribute("Debug")] [assembly: System.Reflection.AssemblyFileVersionAttribute("1.0.0.0")] -[assembly: System.Reflection.AssemblyInformationalVersionAttribute("1.0.0+cf992d544c838206c483289f3baa0c85552f7539")] +[assembly: System.Reflection.AssemblyInformationalVersionAttribute("1.0.0+5454f03ddb4b3eb2300fa4d7dde94814ffd7c607")] [assembly: System.Reflection.AssemblyProductAttribute("MyHelloWorld.Tests")] [assembly: System.Reflection.AssemblyTitleAttribute("MyHelloWorld.Tests")] [assembly: System.Reflection.AssemblyVersionAttribute("1.0.0.0")] diff --git a/MyHelloWorld.Tests/obj/Debug/net8.0/MyHelloWorld.Tests.AssemblyInfoInputs.cache b/MyHelloWorld.Tests/obj/Debug/net8.0/MyHelloWorld.Tests.AssemblyInfoInputs.cache index 21712ad..fb01c97 100644 --- a/MyHelloWorld.Tests/obj/Debug/net8.0/MyHelloWorld.Tests.AssemblyInfoInputs.cache +++ b/MyHelloWorld.Tests/obj/Debug/net8.0/MyHelloWorld.Tests.AssemblyInfoInputs.cache @@ -1 +1 @@ -cd7cd6d89224ce4f2141ef3b9a0e34a6e8261f98f03df22fedfa5203ecf39536 +e906e9e895a27502cddb2517d263bd5de60a1635334d4fe6ed7c2e3d25606bb7 diff --git a/MyHelloWorld.Tests/obj/Debug/net8.0/MyHelloWorld.Tests.assets.cache b/MyHelloWorld.Tests/obj/Debug/net8.0/MyHelloWorld.Tests.assets.cache index 667c9f7221592ef65cd70ebad431f01d0f70a8bf..f3707095b1c4e94c6e0d28488208db0a0e5a997e 100644 GIT binary patch delta 6990 zcmZ`;30M?I7N!j-s3V|q44|O#8n6cjyhcTFRn%|@iV30!cwq1V72**^A)Z80hNmK^ z9Nr>whyz}DYocO;nnZIbnq)W0u5QfkX0K>=U-gt_PfwTMSJu2&|Nqxt)itkXhRgfy zn-19PVS$+Y*Zj0$(hcGFjQpoT*PCX}bq`!-SF@n<-nA_=1{B9sEFU}bl$~80 zI~bYQ3tEfYnVLiDw*2Ag3y3XbU%j9`tjMp0g|~BRw-CHB0|iW=49T zAy^-z4{^XbR$+6)wi=r|oHuv~o1ql{-vSK=Ux$3m`oggwt#e?oe&B1yRx;|e4MzoR zJxqok5D|QZPVG`ZIOM4tjG59EhE3=ylt6jHOsJj^FYJcgs4i|hkg*3_5w=~}im{b| zDQ+gbNb!Nkx3%Cq(NoyVu%#4RMzQ6R-is6soS)?d1rY|Jf?@aBV2N&IWR$R3v1UtLu1QNF`6nOr?g-CUx(GiIy!23i zw87Jd>H&W3dScb+3kBKzg`b##KPw5aH^nUcg&BBC$62+I3{<388+gVH{M80;Wx!Hq z!iArif#*sBh_lVYFU-K-=r}7ck^#ePYXg602L54#w=!UzAG_&xM8Tg%!v*INgh)uIL@IPjN z+#%#Lc#XF*V5xfHIssuOgcV`~Y}>Jsw|g5U9Ujg%i*Iny_7u%3Au5>Q$$Tqw{tg^= zTN}2ORZBq)*R|u&9hG!gm~IxGIOz5i%?hk!b#c12)eanXM;o@4RhKyFvFbD&dM70v zUM@0=&K$H0MYB3CSrryrTXp5IJKM0Wtdi@XduF(<3y0oSNr(K*Q#v;e+MS}=?EvXn zb)p9c?WsiL!ghfvb3P3JQU9u*>9icSmy!*dq$J3Q_ko}vdcI>ZHPs^7M6Z>+Q{V0>&tY~{D-el8Y)2cX8$6@)a zuu3SaGw7eaJ~IIvh5kwf=D0Gkht;_eISP8J@B|%8cR6!jndm1!H)0@1AxK5RvWm*Y z&hjH88aN8UDhfL2A>@Knu8)?K@eoAF%lH6{*Gr#tF1GQ2=i@s;`*j^)>jy4cCq%0; z20~C>A4txf3=>a#!iWuyi0-PYJqWc6sCIkE5i}6Ac8Hsr=3vNPTjj1cGDLu6`wgI3 z=jp{YBosPqf;H=XRHcnjyS`F&WDsO*C{;B+6pe3!+_iJ4X$^iFY6n#teN}aa!Q+k9 zsyc&FClz8R41q!HG12U|5AVab-MVmM~x^Nr&$$76m42uBBjK7U%b2^`d0n9oL3 z06aJPz_a}5ZV?=0B<81}|NgLU>nN`%4k}uJuu%b!v(+9tZJVl{$brQ`&bBpPv7FIK z0$dF153OCD;O7Ddm|QSioQzQUs^d7+DVVqHSGmarel3_HzO7)s!(ql_eyz0A<)&Hw zQx&WP4r`hKvBA9{$G06kcZ-1ih3W-jI?~sWhhGRuVxmHO21h#y^A*HVVUw}7Tlpl z-yR}&`e^5JsP97V&LV9ZXLKGIidJ@;&lz2S`CREKG>vfvVb>)8g_w~WPUkQ)EGMsN ztOs1!74Ef&16wSB%jf_Y8Qv9U6pz*};lMKSfcC~;re>&?q%35;V>0xE)g=+C73Dor zQOGY_ZJ}&;C&&r1huU$yA#As=s@_u6TVgWwMetnJ+O-V4_cR-qBTT*(E2#PRv6o** zD={WtN>*W?jcqmf?Y(JSgRkW59E?eMQ?he0PuL$|PuOdbJqY&v<_0Rn!;hs6NMw#6NRIa zLf)a0&`ONt3db;3Q>el`Q8}?OjYdm$gI10^Ff$a;<*{HkCL4QKgpJGpz*2r$az!M&jRo7XX z_e`C$u?0uvr|%BNYNzim=E>=MJ%3PLu?_nkhy594tNB@I{2WK+9=_nH+@~t+Fya@F zF`%uV5~@^qz)|>;D#*`C5kB&XaICgFgw^|kuTMwtHG7I*aTLB*dcb(6q;UUavhEuW z>mg;ac_G=nFI4&Yx#D9E>xl~M5M}w{`F4Zy#)yI6a@gNd zHhW?izxwxmz27PSHyotDUDZ!K>+UQJCVzQ)8SL88^7pLe@1>_@^*0&%)EC|i8uxz< C*beys delta 6432 zcmZ`;30M?I7G?}BkTA>uBDa7BWDpQU-HZuB);pl07*q@b8bdq~P@`@Xbz(d~<$B7f z7y(ff#R0?t)+LB)by@vIwcMf+sF!xSClWu|& z7ZVv384Y6#Jz#c>rn%OsXKxh;=b~=FgXnImb?|$10Jk2^0$}U~Zy4CmMYVzCoQg1~ z!Vy#&9Rx-FPFsDNXU9DC;EE9|fhXfVVc94x{F0mw4e4t5V^jjSl_Ku075G$+!-!)u zjxCThX&S^$^Ml84MRVIQLmb>)Kfx!$+m3_qD&a{o;i=*F#00JiGXk#~pI+ney%>q-KHf7uOAUR; zCUEtPw_m~|evf7fekR6ipu9$m#IK3>do)uGE?0#$9$?&N372@bjT_A!WE?Z)v|uED zt-N2`IN|&bG2W*V9`VxT2Uk30B8b}i-$-koXV zxx0*akMcS&65snc1mDgyH~u8Q!;El}-{TYU?7+cuAt~L=J;0fO{}rDIZvA#gW|+7i z82+OKFHVVtK!={RQ~1EWTiu{C(~J8X)BIhc>Buy5KQa6t6t{MYJY5*Zi4j9!WI0@0z*C41Yp#YeyL~!^HiQ;s280mYSsNJi8mo*ZYO>|82`J z%QADnGWa(NTbs?@EED%1hW{?XE#-uUWIfjZGR;$orevm>`ya!fQQX>)=FT#4e=z*H z1h>=_nwGUDd1naMLxoS|dRRRJ=a{)J41bB@Eyy9)s}=s3W8&-?&Pi}fP14xJA7xjj zagb;l=bAZ3hC5N*+SrP6Ox(*1e?@{@YHD)SkTJo!PiLl4OEmF$X3mA-8j4$+V2^nw zPRnpt32v!L8l`xjZcO7Y(X`J$#C2o12gR*TuxUXP*PY>>50I7QROW<#*68-F=MK1$CwcvcrkAXx#crG%qZSyg0~s*M zGC-oi&!YrO_d`Y*M!>NVM-1c}YP-uJ{Z)|Or3B7>#V(__#))cp0}A%xk@%inEuk{~FdW;6K=?)!DKPvchGMw=@;BYvN@Y zdStAnmm`T(^VZ^#$nACzsLDh5n~||LPu6Q7dcDV28(I)5yW7{nP%zN?qn`Y6038JZ zvipBS1(`!%1$|+vtW_)oRRqI|00)@$vMVfJ=L+|VoZxw3i1%PzhTI0?VDP#uT|A;) zaEtCZy5e|Kf&FK=yl#{K5CwE7=2tYsK6QxLB$3BV-(P_n4ivjJStB1 zNm5{qQ$a>xA9(EX3Y3+^M~p|B_!N^BWD_tioD)&Tl%__!ZKF(4P)@}BO8$h2^5@b? zx=A+5$qLF;$SDKa3pxcA%lWMm&oM9|;vE~$GzHJ8n6Ktn)9C2{&!NyeU4fZ_haC=t zRpF!M?`2gT-ph^Q{+SAjX_#Mw-f_@T<-%@qhHv+>-yGoLCTHDrB#00DT?L~V_zm6b z|DFPxh504I=F4aMysyBTNxpTjL!&Xyf0hDeHs%fFEXsyyVCd%Yx;dB-uP<9cIF}qv z*>F#GDviVKA#h8mcaDM}7c#f3^v+X2=fN{X<-Y0jQ8BSJIusU;2#3zC@;!M0HV}iX z`~#HFD~;|Ai4`vJxMH$w|5*rAw_S`~gjDg?7t^)=1*7;K^C8a3@6sh0m*U9BaSTd# zg@HNPAFkB&hw`UGU~si#>@q~ej>~aQ_Gs(40`tVtfRQ+UghO!LxP4pfN}P#ZKE}D6 z%PPzhm(>`F%NiVK`E?m9cgC*8nb@TO=W;HEm?tjlFcO#bI0TnPy@UAOJ*;#ps~)c3 zfPmPr22bCKfsq+f^ zRKeyjwP8htmt)`?_VDB0i4jK>WJjs&7)E}l7-#X-iPE?)CE~b(@&r{{3)?|L4A^{PhqswHHp+l-Dw5o8LB)>l`YWLkOuFVQo}w|P<&1mUr@z46OhZnnfii77;PUO|3=%GnWN!B*Wx1@Yieh`u549Pnp0wJZN5>kxj}8jx5tQ||5%7Um>F?XLG`VqI35vIIpX)E zKLq$W!|H=xVYd_DUMX0RazAWp{LM iZgX#DbS_GBZ*Bn%lhF=JlSLY-0W*`p2Pm@_8vzMndlzE> diff --git a/MyHelloWorld.Tests/obj/MyHelloWorld.Tests.csproj.nuget.dgspec.json b/MyHelloWorld.Tests/obj/MyHelloWorld.Tests.csproj.nuget.dgspec.json index 452cbde..87e627f 100644 --- a/MyHelloWorld.Tests/obj/MyHelloWorld.Tests.csproj.nuget.dgspec.json +++ b/MyHelloWorld.Tests/obj/MyHelloWorld.Tests.csproj.nuget.dgspec.json @@ -33,8 +33,12 @@ } }, "warningProperties": { - "warnAsError": [ - "NU1605" + "noWarn": [ + "NU1605", + "NU1901", + "NU1902", + "NU1903", + "NU1904" ] }, "restoreAuditProperties": { @@ -55,6 +59,10 @@ "target": "Package", "version": "[17.8.0, )" }, + "Newtonsoft.Json": { + "target": "Package", + "version": "[12.0.3, )" + }, "coverlet.collector": { "target": "Package", "version": "[6.0.0, )" diff --git a/MyHelloWorld.Tests/obj/project.assets.json b/MyHelloWorld.Tests/obj/project.assets.json index e85d954..7e22468 100644 --- a/MyHelloWorld.Tests/obj/project.assets.json +++ b/MyHelloWorld.Tests/obj/project.assets.json @@ -377,7 +377,7 @@ "System.Xml.XDocument": "4.3.0" } }, - "Newtonsoft.Json/13.0.1": { + "Newtonsoft.Json/12.0.3": { "type": "package", "compile": { "lib/netstandard2.0/Newtonsoft.Json.dll": { @@ -2138,10 +2138,10 @@ "netstandard.library.nuspec" ] }, - "Newtonsoft.Json/13.0.1": { - "sha512": "ppPFpBcvxdsfUonNcvITKqLl3bqxWbDCZIzDWHzjpdAHRFfZe0Dw9HmA0+za13IdyrgJwpkDTDA9fHaxOrt20A==", + "Newtonsoft.Json/12.0.3": { + "sha512": "6mgjfnRB4jKMlzHSl+VD+oUc1IebOZabkbyWj2RiTgWwYPPuaK1H97G1sHqGwPlS5npiF5Q0OrxN1wni2n5QWg==", "type": "package", - "path": "newtonsoft.json/13.0.1", + "path": "newtonsoft.json/12.0.3", "files": [ ".nupkg.metadata", ".signature.p7s", @@ -2160,7 +2160,11 @@ "lib/netstandard1.3/Newtonsoft.Json.xml", "lib/netstandard2.0/Newtonsoft.Json.dll", "lib/netstandard2.0/Newtonsoft.Json.xml", - "newtonsoft.json.13.0.1.nupkg.sha512", + "lib/portable-net40+sl5+win8+wp8+wpa81/Newtonsoft.Json.dll", + "lib/portable-net40+sl5+win8+wp8+wpa81/Newtonsoft.Json.xml", + "lib/portable-net45+win8+wp8+wpa81/Newtonsoft.Json.dll", + "lib/portable-net45+win8+wp8+wpa81/Newtonsoft.Json.xml", + "newtonsoft.json.12.0.3.nupkg.sha512", "newtonsoft.json.nuspec", "packageIcon.png" ] @@ -5541,6 +5545,7 @@ "net8.0": [ "JunitXml.TestLogger >= 8.0.0", "Microsoft.NET.Test.Sdk >= 17.8.0", + "Newtonsoft.Json >= 12.0.3", "SecDevOpsLab >= 1.0.0", "coverlet.collector >= 6.0.0", "xunit >= 2.5.3", @@ -5579,8 +5584,12 @@ } }, "warningProperties": { - "warnAsError": [ - "NU1605" + "noWarn": [ + "NU1605", + "NU1901", + "NU1902", + "NU1903", + "NU1904" ] }, "restoreAuditProperties": { @@ -5601,6 +5610,10 @@ "target": "Package", "version": "[17.8.0, )" }, + "Newtonsoft.Json": { + "target": "Package", + "version": "[12.0.3, )" + }, "coverlet.collector": { "target": "Package", "version": "[6.0.0, )" diff --git a/MyHelloWorld.Tests/obj/project.nuget.cache b/MyHelloWorld.Tests/obj/project.nuget.cache index 050bc32..25eed81 100644 --- a/MyHelloWorld.Tests/obj/project.nuget.cache +++ b/MyHelloWorld.Tests/obj/project.nuget.cache @@ -1,6 +1,6 @@ { "version": 2, - "dgSpecHash": "cMCqBPi36D8=", + "dgSpecHash": "AxMlimmOwXI=", "success": true, "projectFilePath": "C:\\Users\\HermanH\\SecDevOpsLab\\MyHelloWorld.Tests\\MyHelloWorld.Tests.csproj", "expectedPackageFiles": [ @@ -14,7 +14,7 @@ "C:\\Users\\HermanH\\.nuget\\packages\\microsoft.testplatform.testhost\\17.8.0\\microsoft.testplatform.testhost.17.8.0.nupkg.sha512", "C:\\Users\\HermanH\\.nuget\\packages\\microsoft.win32.primitives\\4.3.0\\microsoft.win32.primitives.4.3.0.nupkg.sha512", "C:\\Users\\HermanH\\.nuget\\packages\\netstandard.library\\1.6.1\\netstandard.library.1.6.1.nupkg.sha512", - "C:\\Users\\HermanH\\.nuget\\packages\\newtonsoft.json\\13.0.1\\newtonsoft.json.13.0.1.nupkg.sha512", + "C:\\Users\\HermanH\\.nuget\\packages\\newtonsoft.json\\12.0.3\\newtonsoft.json.12.0.3.nupkg.sha512", "C:\\Users\\HermanH\\.nuget\\packages\\nuget.frameworks\\6.5.0\\nuget.frameworks.6.5.0.nupkg.sha512", "C:\\Users\\HermanH\\.nuget\\packages\\runtime.debian.8-x64.runtime.native.system.security.cryptography.openssl\\4.3.0\\runtime.debian.8-x64.runtime.native.system.security.cryptography.openssl.4.3.0.nupkg.sha512", "C:\\Users\\HermanH\\.nuget\\packages\\runtime.fedora.23-x64.runtime.native.system.security.cryptography.openssl\\4.3.0\\runtime.fedora.23-x64.runtime.native.system.security.cryptography.openssl.4.3.0.nupkg.sha512",