Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Audit fix (example: dotnet nuget audit fix) #13372

Open
nkolev92 opened this issue Apr 3, 2024 · 0 comments
Open

Audit fix (example: dotnet nuget audit fix) #13372

nkolev92 opened this issue Apr 3, 2024 · 0 comments
Assignees

Comments

@nkolev92
Copy link
Member

nkolev92 commented Apr 3, 2024

NuGet Product(s) Involved

Visual Studio Package Management UI, dotnet.exe

The Elevator Pitch

Provide an automated way for fixing project graphs with vulnerabilities in them.

Frequently when transitive packages have vulnerabilities, updating the pasckages becomes a challenge.
Should I update the top level package? Update the vulnerable package only?
Is that enough?
Does that bring new vulnerabilities?

Doing this perfectly will be challenging, but something is better than nothing :D

Additional Context and Details

Mentioned in #11549 and part of the #8087 epic.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants