Skip to content

Set NuGetAuditMode to "all" to enable vulnerable transitive dependencies warnings#2277

Merged
kevinchalet merged 1 commit intoopeniddict:devfrom
kevinchalet:nuget_auditing
Mar 20, 2025
Merged

Set NuGetAuditMode to "all" to enable vulnerable transitive dependencies warnings#2277
kevinchalet merged 1 commit intoopeniddict:devfrom
kevinchalet:nuget_auditing

Conversation

@kevinchalet
Copy link
Member

In OpenIddict 7.0, we'll change the way we're handling vulnerable transitive dependencies: instead of asking the end user to override vulnerable versions in their own project, the OpenIddict 7.0 packages will now include explicit/direct references for all the packages that are flagged as vulnerable by NuGet. While it's unlikely we'll go as far as releasing a new OpenIddict version each time an upstream dependency is flagged as vulnerable, it will at least ensure that OpenIddict's dependencies graph is safe every time a new release ships.

@kevinchalet kevinchalet merged commit d9e4486 into openiddict:dev Mar 20, 2025
6 checks passed
@kevinchalet kevinchalet deleted the nuget_auditing branch March 20, 2025 15:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant