-
Notifications
You must be signed in to change notification settings - Fork 6.1k
Open
Labels
⌚ Not TriagedNot triagedNot triageddotnet-cli/subsvcin-prThis issue will be closed (fixed) by an active pull request.This issue will be closed (fixed) by an active pull request.
Description
Currently nuget.org is the only package source that we're aware of that provides a vulnerability database for NuGet to run Audit with, however, NuGet will run Audit as long as any source provides the VulnerabilityInfo resource, as documented in the NuGet product's Server API documentation.
Additionally, I think it would be valuable to link to the NuGet product docs page on audit, so customers can get more info, see other options, etc: https://learn.microsoft.com/en-us/nuget/concepts/auditing-packages
Document Details
⚠ Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.
- ID: 0b256dc4-c4ad-c115-f4e2-40310bc3505a
- Version Independent ID: 0b993779-65a2-6092-4047-2fc2ec16170b
- Content: dotnet restore command - .NET CLI
- Content Source: docs/core/tools/dotnet-restore.md
- Service: dotnet-fundamentals
- GitHub Login: @tdykstra
- Microsoft Alias: tdykstra
Metadata
Metadata
Assignees
Labels
⌚ Not TriagedNot triagedNot triageddotnet-cli/subsvcin-prThis issue will be closed (fixed) by an active pull request.This issue will be closed (fixed) by an active pull request.
Type
Projects
Status
👀 In review