Skip to content

chore: override vulnerable SQLitePCLRaw native dependency - #3

Merged
DevD4v3 merged 1 commit into
masterfrom
patch-1
Oct 2, 2026
Merged

DevD4v3 merged 1 commit into
masterfrom
patch-1

Conversation

@DevD4v3

@DevD4v3 DevD4v3 commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Microsoft.EntityFrameworkCore.Sqlite depends transitively on SQLitePCLRaw.bundle_e_sqlite3 (>= 2.1.11), which resolves to a vulnerable SQLite native library version affected by CVE-2025-6965 (GHSA-2m69-gcr7-jv3q).

Add an explicit reference to SQLitePCLRaw.lib.e_sqlite3 3.50.3 to override the transitive dependency and ensure a patched SQLite native binary is used until Microsoft.EntityFrameworkCore.Sqlite updates its dependency chain.

@DevD4v3
DevD4v3 merged commit 9496cdc into master Oct 2, 2026
1 check passed
@DevD4v3
DevD4v3 deleted the patch-1 branch October 2, 2026 11:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant