Nuget package vulnerable flag misuse #13675
AndersBillLinden
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Some packages, fortunately only a few, tag an old version of a package as vulnerable (just because it is old).
In this way, we receive warnings that are unnecessary because the project isn't less secure if the only concern is upgrading to the newest version.
We encounter this issue with the Npgsql package (Postgres support).
Package developers need to push new versions differently.
Perhaps the vulnerability flag should be accompanied by a link to a security breach forum thread, as it otherwise loses its value.
Beta Was this translation helpful? Give feedback.
All reactions