Skip to content

Conversation

@xtqqczze
Copy link
Contributor

No description provided.

@xtqqczze xtqqczze marked this pull request as ready for review September 28, 2025 17:32
@xtqqczze
Copy link
Contributor Author

I wonder why this has not been updated by @dotnet-maestro

@mmitche
Copy link
Member

mmitche commented Sep 29, 2025

@xtqqczze Maestro only does .NET specific package flow, not general dependabot style flow.

@xtqqczze
Copy link
Contributor Author

coverlet.collector 1.0.1 is affected by vulnerabilities through its dependency on Newtonsoft.Json, as reported by Mend.io.

@mmitche mmitche merged commit b31d1d5 into dotnet:main Oct 1, 2025
10 checks passed
@xtqqczze
Copy link
Contributor Author

xtqqczze commented Oct 1, 2025

@xtqqczze Maestro only does .NET specific package flow, not general dependabot style flow.

@mmitche Can we use dependabot to keep coverlet.collector updated?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants