<https://pulumi-community.slack.com/archives/CQ2QF...
# general
q
b
It looks like we build language-dotnet with 1.24.7, and this CVE is for <1.24.13 - I'll ask the team 🙂
OK, this has been updated, and will be fixed in the next release!
1
q
Thanks for taking a look. In dockerfile I remove java and yaml directories because they have similar issues
@billowy-telephone-40262 when approx. pulumi will be released?
b
we release every week, so if we've missed this week's release then it'll be mid next week 🙂
🙏 1
q
Hi, I was able to bump pulumi and pulumi-azure-native but there are still CVEs from stdlib
Hi guys, it seems there is new high scored CVE, could you take a look? Thanks, Grzesiek
e
Again, we don't use any cryto functions in the dotnet runtime so I wouldn't count this as risky. But it should get picked up in the weeks auto dependency updates for the next release.
👍 1