CycloneDX / CycloneDX/cyclonedx-dotnet

Add results of Nuget Vulnerabilities scan to bom?

Open
#805 0 comments 3 reactions 0 assignees View on GitHub
Dominant language
C#
Stars
294
Forks
123
PR merge metrics
No merged PRs in 30d

Description

See here: https://devblogs.microsoft.com/nuget/how-to-scan-nuget-packages-for-security-vulnerabilities/

Contributor guide

Open the contributing guide

Research direction

Start with the linked NuGet vulnerability-scanning guidance, then locate the project's BOM generation path and determine where scan results could be represented. Done means the relevant NuGet vulnerability results are included in generated CycloneDX BOMs, with coverage verified by appropriate tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.