You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Provide an automated way for fixing project graphs with vulnerabilities in them.
Frequently when transitive packages have vulnerabilities, updating the pasckages becomes a challenge.
Should I update the top level package? Update the vulnerable package only?
Is that enough?
Does that bring new vulnerabilities?
Doing this perfectly will be challenging, but something is better than nothing :D
NuGet Product(s) Involved
Visual Studio Package Management UI, dotnet.exe
The Elevator Pitch
Provide an automated way for fixing project graphs with vulnerabilities in them.
Frequently when transitive packages have vulnerabilities, updating the pasckages becomes a challenge.
Should I update the top level package? Update the vulnerable package only?
Is that enough?
Does that bring new vulnerabilities?
Doing this perfectly will be challenging, but something is better than nothing :D
Additional Context and Details
Mentioned in #11549 and part of the #8087 epic.
The text was updated successfully, but these errors were encountered: