Init Sample: Create .NET vulnerable dependencies sample repository #2
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR transforms the repository into a complete sample demonstrating vulnerable dependencies in a .NET solution with Central Package Management (CPM).
What's Added
Solution Structure:
VulnerableWebApi
- ASP.NET Core Web API with JWT authentication and JSON handlingVulnerableLibrary
- Class library with logging and token processing capabilitiesVulnerableConsole
- Console application with database connectivityCentral Package Management:
Directory.Packages.props
for centralized version controlVulnerable Dependencies:
The sample includes intentionally vulnerable packages to demonstrate security scanning:
Newtonsoft.Json
Microsoft.Data.SqlClient
System.IdentityModel.Tokens.Jwt
Microsoft.AspNetCore.Authentication.JwtBearer
Security Warnings Generated:
Building the solution produces 12+ vulnerability warnings (NU1902/NU1903), demonstrating how .NET's built-in security scanning detects vulnerable packages during restore and build operations.
Sample Code:
Each project includes realistic code that uses the vulnerable dependencies:
Documentation:
Comprehensive README.md covering:
This sample serves as an educational tool for understanding dependency vulnerabilities and testing security scanning tools in .NET environments.
Fixes #1.
✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.