CycloneDX / CycloneDX/cyclonedx-dotnet
Add results of Nuget Vulnerabilities scan to bom?
Open
- Dominant language
- C#
- Stars
- 294
- Forks
- 123
- PR merge metrics
- No merged PRs in 30d
Description
See here: https://devblogs.microsoft.com/nuget/how-to-scan-nuget-packages-for-security-vulnerabilities/
Contributor guide
Research direction
Start with the linked NuGet vulnerability-scanning guidance, then locate the project's BOM generation path and determine where scan results could be represented. Done means the relevant NuGet vulnerability results are included in generated CycloneDX BOMs, with coverage verified by appropriate tests.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- csharp
- Domain
- security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100