Develop process to validate SDK does not include any vulnerable components
Open
Area-Infrastructure
untriaged
- Dominant language
- C#
- Stars
- 3.2k
- Forks
- 1.3k
- PR merge metrics
- PR metrics pending
Description
A validation process is needed to ensure the SDK does not include any vulnerable components. This includes pre-disclosed vulnerabilities. See https://github.com/dotnet/dotnet-docker/issues/5325 and https://github.com/dotnet/sdk/issues/30659 for the background and how these may be "false positives". This validation should be automated and run as part of CI to ensure the SDK is in a clean state prior to shipping.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.