YamlDotNet 3.8.0-pre197

The ID prefix of this package has been reserved for one of the owners of this package by NuGet.org. Prefix Reserved
Details
Advisory: https://github.com/advisories/GHSA-rpch-cqj9-h65r Severity: high
Suggested Alternatives

YamlDotNet 9.1.4

Additional Details

YamlDotNet version 4.3.2 and earlier contains a Insecure Direct Object Reference vulnerability in The default behavior of Deserializer.Deserialize() will deserialize user-controlled types in the line "currentType = Type.GetType(nodeEvent.Tag.Substring(1), throwOnError: false);" and blindly instantiates them. that can result in Code execution in the context of the running process. This attack appear to be exploitable via Victim must parse a specially-crafted YAML file. This vulnerability has been fixed in 5.0.0.

This is a prerelease version of YamlDotNet.
There is a newer version of this package available.
See the version list below for details.
The owner has unlisted this package. This could mean that the package is deprecated, has security vulnerabilities or shouldn't be used anymore.

Requires NuGet 2.8 or higher.

dotnet add package YamlDotNet --version 3.8.0-pre197
NuGet\Install-Package YamlDotNet -Version 3.8.0-pre197
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="YamlDotNet" Version="3.8.0-pre197" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
paket add YamlDotNet --version 3.8.0-pre197
#r "nuget: YamlDotNet, 3.8.0-pre197"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
// Install YamlDotNet as a Cake Addin
#addin nuget:?package=YamlDotNet&version=3.8.0-pre197&prerelease

// Install YamlDotNet as a Cake Tool
#tool nuget:?package=YamlDotNet&version=3.8.0-pre197&prerelease

A .NET library for YAML. YamlDotNet provides low level parsing and emitting of YAML as well as a high level object model similar to XmlDocument.

Product Compatible and additional computed target framework versions.
.NET Framework net35 is compatible.  net40 was computed.  net403 was computed.  net45 was computed.  net451 was computed.  net452 was computed.  net46 was computed.  net461 was computed.  net462 was computed.  net463 was computed.  net47 was computed.  net471 was computed.  net472 was computed.  net48 was computed.  net481 was computed. 
.NETPlatform dotnet is compatible. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

NuGet packages (687)

Showing the top 5 NuGet packages that depend on YamlDotNet:

Package Downloads
KubernetesClient

Client library for the Kubernetes open source container orchestrator.

NJsonSchema.Yaml

JSON Schema reader, generator and validator for .NET

KubernetesClient.Models

Client library for the Kubernetes open source container orchestrator.

NetEscapades.Configuration.Yaml

YAML configuration provider implementation to use with Microsoft.Extensions.Configuration.

Microsoft.Azure.WebJobs.Extensions.OpenApi The ID prefix of this package has been reserved for one of the owners of this package by NuGet.org.

This package helps render OpenAPI document and Swagger UI of Azure Functions endpoints through the in-proc worker.

GitHub repositories (203)

Showing the top 5 popular GitHub repositories that depend on YamlDotNet:

Repository Stars
DevToys-app/DevToys
A Swiss Army knife for developers.
microsoft/semantic-kernel
Integrate cutting-edge LLM technology quickly and easily into your apps
bitwarden/server
The core infrastructure backend (API, database, Docker, etc).
Jackett/Jackett
API Support for your favorite torrent trackers
unoplatform/uno
Build Mobile, Desktop and WebAssembly apps with C# and XAML. Today. Open source and professionally supported.
Version Downloads Last updated
15.1.2 138,443 2/26/2024
15.1.1 194,522 2/4/2024
15.1.0 253,010 1/23/2024
13.7.1 3,092,094 10/15/2023
13.7.0 66,806 10/10/2023
13.5.2 51,653 10/5/2023
13.5.1 16,305 10/5/2023
13.5.0 1,917 10/5/2023
13.4.0 337,373 9/20/2023
13.3.1 1,407,180 8/28/2023
13.2.0 230,954 8/14/2023
13.1.1 2,607,967 6/17/2023
13.1.0 1,549,546 4/16/2023
13.0.2 908,009 3/11/2023
13.0.1 2,855,977 2/19/2023
13.0.0 684,733 2/7/2023
12.3.1 4,663,868 12/19/2022
12.3.0 2,994 12/19/2022
12.2.1 204,728 12/14/2022
12.2.0 242,686 12/9/2022
12.1.0 397,135 12/5/2022
12.0.2 1,465,567 10/7/2022
12.0.1 3,168,219 9/17/2022
12.0.0 3,076,404 7/23/2022
11.2.1 63,563,118 6/28/2021
11.2.0 528,327 6/13/2021
11.1.3-nullable-enums-0003 29,903 4/9/2021
11.1.1 3,030,750 4/9/2021
11.1.0 32,503 4/8/2021
11.0.1 61,887 4/1/2021
10.1.0 56,261 3/31/2021
10.0.0 43,901 3/27/2021
9.1.4 7,977,719 1/15/2021
8.1.2 23,794,511 5/28/2020
8.1.0 5,378,925 1/18/2020
8.0.0 6,518,132 10/19/2019
7.0.0 687,411 9/28/2019
6.1.2 2,783,976 7/20/2019
6.1.1 546,776 6/4/2019
6.0.0 12,227,766 3/15/2019
5.4.0 355,483 2/12/2019
5.3.1 7,078 2/12/2019
5.3.0 1,250,368 12/5/2018
5.1.0 1,879,645 9/21/2018