microsoft / microsoft/winget-cli

Checking for known vulnerabilities

Open
#2,204 10 comments 7 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Catalog-Health Issue-Feature
Dominant language
C++
Stars
26.4k
Forks
1.8k
Avg merge
1d 11h
Merged PRs (30d)
15

Description

Description of the new feature / enhancement

winget should be able to check if there are known vulnerabilities for installed applications.

Proposed technical implementation details

Similar to npm audit which uses the GitHub advisory database, winget could list installed applications with known vulnerabilities with the command winget audit.

It should then list:

  • Severity
  • Vulnerabilty type
  • Link to security advisory (more information)

It should also show if there is a newer version available which fixes the vulnerability.

The main technical difficulty would be choosing and the maintaining database backend. Maybe the Github advisory database could be expanded.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing how winget commands are structured and how the GitHub Advisory Database could support the proposed audit flow, using npm audit as the stated comparison. Done would mean a defined winget audit command that lists installed applications with severity, vulnerability type, advisory links, and whether a newer fixing version exists.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp, github
Domain
cli, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.