Skip to content

Bump AutoMapper from 15.1.0 to 15.1.3#6

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/nuget/MissionCriticalDemo/MissionCriticalDemo.Messages/AutoMapper-15.1.3
Open

Bump AutoMapper from 15.1.0 to 15.1.3#6
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/nuget/MissionCriticalDemo/MissionCriticalDemo.Messages/AutoMapper-15.1.3

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot bot commented on behalf of github Mar 29, 2026

Updated AutoMapper from 15.1.0 to 15.1.3.

Release notes

Sourced from AutoMapper's releases.

15.1.3

What's Changed

Security

Fixed an issue where certain cyclic or self-referential object graphs could trigger uncontrolled recursion during mapping, potentially resulting in stack exhaustion and denial of service.

Applications that process untrusted or attacker-controlled object graphs through affected mapping paths may be impacted.

Users should upgrade to this release.

Security advisory: GHSA-rvv3-g6hj-g44x

Thanks to @​skdishansachin for responsibly disclosing this issue.

Full Changelog: LuckyPennySoftware/AutoMapper@v15.1.0...v15.1.3

15.1.2

What's Changed

Security

Fixed an issue where certain cyclic or self-referential object graphs could trigger uncontrolled recursion during mapping, potentially resulting in stack exhaustion and denial of service.

Applications that process untrusted or attacker-controlled object graphs through affected mapping paths may be impacted.

Users should upgrade to this release.

Security advisory: GHSA-rvv3-g6hj-g44x

Thanks to @​skdishansachin for responsibly disclosing this issue.

Full Changelog: LuckyPennySoftware/AutoMapper@v16.1.1...v15.1.2

15.1.1

What's Changed

Security

Fixed an issue where certain cyclic or self-referential object graphs could trigger uncontrolled recursion during mapping, potentially resulting in stack exhaustion and denial of service.

Applications that process untrusted or attacker-controlled object graphs through affected mapping paths may be impacted.

Users should upgrade to this release.

Security advisory: GHSA-rvv3-g6hj-g44x

Thanks to @​skdishansachin for responsibly disclosing this issue.

Full Changelog: LuckyPennySoftware/AutoMapper@v16.1.1...v15.1.1

Commits viewable in compare view.

@dependabot dependabot bot added dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code labels Mar 29, 2026
@loekd
Copy link
Copy Markdown
Owner

loekd commented Apr 6, 2026

@dependabot rebase

---
updated-dependencies:
- dependency-name: AutoMapper
  dependency-version: 15.1.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/nuget/MissionCriticalDemo/MissionCriticalDemo.Messages/AutoMapper-15.1.3 branch from 1427bd2 to 770bf75 Compare April 6, 2026 06:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant