-
Notifications
You must be signed in to change notification settings - Fork 370
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Scan nuget #51
Comments
Wow. Thanks. Need to take on a spin. If we can run as a build step in ci/cd pipeline this will rock. I love GitHub's dependabot but we have azure DevOps repos. So making this a build output updater and potentially a build failure cause would be awesome. |
@vbjay BetterScan uses osv-scanner and integrates with Azure DevOps. So as soon as this feature gets released, we can bug Marcinguy to pull in the update. |
@oliverchang When are we likely to see this get released? |
@another-rex Let's cut a release this week! |
fwiw ideally #124 should be addressed before a new release is cut |
oh and #132 too 😅 |
This is now released! https://github.com/google/osv-scanner/releases/tag/v1.1.0 Note that this release only includes support for |
Hi! First of all thank you for the awesome work!
With the latest version, using |
Can you create a new issue linking to this one test demoing this discrepancy along with osv results vs |
Basically trying to determine if the scanner just needs to pull results from dotnet command run or if both have limitations. |
+1, please open a new issue so we can track it :) |
Opened in #298 , let me know if some things are not so well explained 👍 |
Report on nuget package usage that has a vulnerability.
https://devblogs.microsoft.com/nuget/how-to-scan-nuget-packages-for-security-vulnerabilities/
The text was updated successfully, but these errors were encountered: