We found that adding dependency scanning step into the workflow, release or not can prevent some possible attacks. ```yml - name: Scan for Vulnerable Dependencies run: dotnet list package --vulnerable --include-transitive ```