You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
While there is no problem at all if nuget.org is used with the default template, I think that makes it easier for consumers to make a mistake that makes their project vulnerable.
It was updated in #725 to prevent dependency confusion attack.
While the template would build just find, it's unclear what analyzer authors should do for dogfooding.
Analyzers authors obviously don't own dotnet-tools or dotnet-public feeds.
It's also now discouraged to mix public and private feeds.
cc: @mmitche
The text was updated successfully, but these errors were encountered: