Open
Description
Version
4.14.8
Describe the bug
There is a security vulnerability detected via Component Governance in DevOps. The severity is marked as Critical.
The details about this vulnerability:
In this SDK, the jsonpickle package is limited (>=1.2,<1.5), it is possible to use the latest version to avoid this security vulnerability?
Use version ranges 3rd party deps by cognifloyd · Pull Request #1468 · microsoft/botbuilder-python (github.com)
It is a blocking issue for our production service. Please help resolve it ASAP. Thanks.
To Reproduce
Use echo bot as an example, trigger a build in Azure DevOps, and enable Component Governance
Expected behavior
Pass Component Governance