Skip to content

dotnet update package --vulnerable (Audit fix) #13372

@nkolev92

Description

@nkolev92

NuGet Product(s) Involved

Visual Studio Package Management UI, dotnet.exe

The Elevator Pitch

Provide an automated way for fixing project graphs with vulnerabilities in them.

Frequently when transitive packages have vulnerabilities, updating the pasckages becomes a challenge.
Should I update the top level package? Update the vulnerable package only?
Is that enough?
Does that bring new vulnerabilities?

Doing this perfectly will be challenging, but something is better than nothing :D

Additional Context and Details

Mentioned in #11549 and part of the #8087 epic.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions