Skip to content

update System.Net.Http to 4.3.3#1

Merged
felickz merged 2 commits into
mainfrom
update-system-net-http
Oct 31, 2025
Merged

update System.Net.Http to 4.3.3#1
felickz merged 2 commits into
mainfrom
update-system-net-http

Conversation

@felickz
Copy link
Copy Markdown

@felickz felickz commented Oct 31, 2025

No description provided.

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Oct 31, 2025

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
nuget/System.Net.Http 4.3.3 🟢 3.8
Details
CheckScoreReason
Binary-Artifacts🟢 10no binaries found in the repo
Code-Review🟢 5Found 2/4 approved changesets -- score normalized to 5
Pinned-Dependencies⚠️ -1no dependencies found
Token-Permissions⚠️ -1No tokens found
Dangerous-Workflow⚠️ -1no workflows found
Packaging⚠️ -1packaging workflow not detected
Maintained⚠️ 0project is archived
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
Vulnerabilities🟢 100 existing vulnerabilities detected
License⚠️ 0license file not detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Security-Policy⚠️ 0security policy file not detected
nuget/runtime.debian.8-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.fedora.23-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.fedora.24-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.opensuse.13.2-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.opensuse.42.1-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.osx.10.10-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.rhel.7-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.ubuntu.14.04-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.ubuntu.16.04-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.ubuntu.16.10-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/System.Net.Http 4.3.3 🟢 3.8
Details
CheckScoreReason
Binary-Artifacts🟢 10no binaries found in the repo
Code-Review🟢 5Found 2/4 approved changesets -- score normalized to 5
Pinned-Dependencies⚠️ -1no dependencies found
Token-Permissions⚠️ -1No tokens found
Dangerous-Workflow⚠️ -1no workflows found
Packaging⚠️ -1packaging workflow not detected
Maintained⚠️ 0project is archived
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
Vulnerabilities🟢 100 existing vulnerabilities detected
License⚠️ 0license file not detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Security-Policy⚠️ 0security policy file not detected
nuget/runtime.debian.8-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.fedora.23-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.fedora.24-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.opensuse.13.2-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.opensuse.42.1-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.osx.10.10-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.rhel.7-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.ubuntu.14.04-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.ubuntu.16.04-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown
nuget/runtime.ubuntu.16.10-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2 UnknownUnknown

Scanned Files

  • VulnerableApi/VulnerableApi.csproj
  • VulnerableLibrary/VulnerableLibrary.csproj

@felickz felickz merged commit c44e381 into main Oct 31, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant