Skip to content

Conversation

@DavidBoike
Copy link
Member

@DavidBoike DavidBoike commented Apr 23, 2024

Adds NuGetAuditMode = all to the project so that all transitive dependencies with known vulnerabilities will be detected and fixed using available NuGet tooling.

Also adds explicit versions for the detected transitive dependencies to ensure vulnerable dependencies are not shipped.

@DavidBoike DavidBoike changed the base branch from master to release-5.1 April 23, 2024 21:02
@DavidBoike DavidBoike force-pushed the nuget-audit-mode-5.1 branch from b39be8f to 7f50333 Compare April 23, 2024 21:03
@DavidBoike DavidBoike requested a review from tamararivera April 23, 2024 21:03
@DavidBoike DavidBoike self-assigned this Apr 23, 2024
@DavidBoike DavidBoike merged commit 6ae74fb into release-5.1 Apr 24, 2024
@DavidBoike DavidBoike deleted the nuget-audit-mode-5.1 branch April 24, 2024 21:30
@DavidBoike DavidBoike added this to the 5.1.1 milestone Apr 25, 2024
@DavidBoike DavidBoike changed the title Add NuGetAuditMode = all and bump necessary versions (release-5.1) Vulnerabilities in transitive dependencies Apr 29, 2024
@DavidBoike DavidBoike added the Bug label Apr 29, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants