Skip to content

Fix warning "Component Governance detected 5 security related alerts at or above 'High' severity." #22252

Closed
@wtgodbe

Description

@wtgodbe

Part of #22240

Happens during component detection. Whole warning text:

##[warning]Component Governance detected 5 security related alerts at or above 'High' severity. Microsoft’s Open Source policy requires that all high and critical security vulnerabilities found by this task be addressed by upgrading vulnerable components. Vulnerabilities in indirect dependencies should be addressed by upgrading the root dependency.

Metadata

Metadata

Assignees

Labels

affected-mostThis issue impacts most of the customersarea-infrastructureIncludes: MSBuild projects/targets, build scripts, CI, Installers and shared frameworkenhancementThis issue represents an ask for new feature or an enhancement to an existing oneseverity-nice-to-haveThis label is used by an internal tool

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions