Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dotnet list package include hash and source for output #11552

Open
erdembayar opened this issue Feb 2, 2022 · 0 comments
Open

dotnet list package include hash and source for output #11552

erdembayar opened this issue Feb 2, 2022 · 0 comments
Labels
Functionality:ListPackage dotnet.exe list package Priority:3 Issues under consideration. With enough upvotes, will be reconsidered to be added to the backlog. Product:dotnet.exe Type:Feature

Comments

@erdembayar
Copy link
Contributor

erdembayar commented Feb 2, 2022

Currently lock file include hash but dotnet list package doesn't.
It's important to have one hash+source to detect/prevent dependency confusion attack.

#11446 (comment)
Given GH is not good at keep track of comments/discussion I'm including screenshot.

image.png

@nkolev92 nkolev92 added Priority:3 Issues under consideration. With enough upvotes, will be reconsidered to be added to the backlog. Type:Feature labels Feb 14, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Functionality:ListPackage dotnet.exe list package Priority:3 Issues under consideration. With enough upvotes, will be reconsidered to be added to the backlog. Product:dotnet.exe Type:Feature
Projects
None yet
Development

No branches or pull requests

4 participants