microsoft / microsoft/winget-cli
Checking for known vulnerabilities
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 26.4k
- Forks
- 1.8k
- Avg merge
- 1d 11h
- Merged PRs (30d)
- 15
Description
Description of the new feature / enhancement
winget should be able to check if there are known vulnerabilities for installed applications.
Proposed technical implementation details
Similar to npm audit which uses the GitHub advisory database, winget could list installed applications with known vulnerabilities with the command winget audit.
It should then list:
- Severity
- Vulnerabilty type
- Link to security advisory (more information)
It should also show if there is a newer version available which fixes the vulnerability.
The main technical difficulty would be choosing and the maintaining database backend. Maybe the Github advisory database could be expanded.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing how winget commands are structured and how the GitHub Advisory Database could support the proposed audit flow, using npm audit as the stated comparison. Done would mean a defined winget audit command that lists installed applications with severity, vulnerability type, advisory links, and whether a newer fixing version exists.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp, github
- Domain
- cli, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100