-
Notifications
You must be signed in to change notification settings - Fork 264
Closed
NuGet/NuGet.Client
#6768Labels
Area:NuGetAuditFunctionality:RestorePriority:2Issues for the current backlog.Issues for the current backlog.Type:Feature
Milestone
Description
NuGet Product(s) Involved
Visual Studio Package Management UI, dotnet.exe
The Elevator Pitch
Provide an automated way for fixing project graphs with vulnerabilities in them.
Frequently when transitive packages have vulnerabilities, updating the pasckages becomes a challenge.
Should I update the top level package? Update the vulnerable package only?
Is that enough?
Does that bring new vulnerabilities?
Doing this perfectly will be challenging, but something is better than nothing :D
Additional Context and Details
Frulfump, cremor, JonDouglas, AndriySvyryd, WeihanLi and 4 more
Metadata
Metadata
Assignees
Labels
Area:NuGetAuditFunctionality:RestorePriority:2Issues for the current backlog.Issues for the current backlog.Type:Feature