.NET transitive dependencies not showing on dependency chart #144979
Unanswered
vmcbaptista
asked this question in
Code Security
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Transitive dependencies are not added to dependency graph even if support for packages.lock.json is enabled.
These lock files must be considered to also detect vulnerabilities in transitive dependencies.
Note tha dependabot recently added support to these lock files, which makes this even more relevant.
Beta Was this translation helpful? Give feedback.
All reactions