-
Notifications
You must be signed in to change notification settings - Fork 306
Open
Labels
bugIndicates an unexpected problem or an unintended behavior.Indicates an unexpected problem or an unintended behavior.needs-triageThe issue has just been created and it has not been reviewed by the team.The issue has just been created and it has not been reviewed by the team.
Description
Version
4.14.8
Describe the bug
There is a security vulnerability detected via Component Governance in DevOps. The severity is marked as Critical.
The details about this vulnerability:
In this SDK, the jsonpickle package is limited (>=1.2,<1.5), it is possible to use the latest version to avoid this security vulnerability?
Use version ranges 3rd party deps by cognifloyd · Pull Request #1468 · microsoft/botbuilder-python (github.com)
It is a blocking issue for our production service. Please help resolve it ASAP. Thanks.
To Reproduce
Use echo bot as an example, trigger a build in Azure DevOps, and enable Component Governance
Expected behavior
Pass Component Governance
Additional context
stabacco, cbts-narayan-maharjan, armen-tractatus, JCramerScultureAI and rfauglas
Metadata
Metadata
Assignees
Labels
bugIndicates an unexpected problem or an unintended behavior.Indicates an unexpected problem or an unintended behavior.needs-triageThe issue has just been created and it has not been reviewed by the team.The issue has just been created and it has not been reviewed by the team.

