Skip to content

Conversation

@meaghanlewis
Copy link
Contributor

@meaghanlewis meaghanlewis commented Dec 2, 2025

Summary

Describe your changes here.

Fixes #39212


Internal previews

📄 File 🔗 Preview link
docs/core/tools/dotnet-restore.md dotnet restore

@meaghanlewis meaghanlewis marked this pull request as ready for review December 3, 2025 20:36
@meaghanlewis meaghanlewis requested a review from a team as a code owner December 3, 2025 20:36
Copilot AI review requested due to automatic review settings December 3, 2025 20:36
Copilot finished reviewing on behalf of meaghanlewis December 3, 2025 20:38
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR clarifies the requirements for security auditing in dotnet restore by improving the documentation around how to retrieve vulnerability datasets.

  • Updated the instruction for configuring the NuGet.org package source to be more specific about using the nuget.config file
  • Added a new paragraph explaining that NuGet.org is currently the only package source providing vulnerability datasets, while noting that any source implementing the VulnerabilityInfo resource can support auditing

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

dotnet restore command notes that NuGetAudit only works with nuget.org

1 participant