Skip to content

Add Scan for Vulnerable Dependencies #4084

@vncoelho

Description

@vncoelho

We found that adding dependency scanning step into the workflow, release or not can prevent some possible attacks.

- name: Scan for Vulnerable Dependencies
  run: dotnet list package --vulnerable --include-transitive

Metadata

Metadata

Assignees

No one assigned

    Labels

    DiscussionInitial issue state - proposed but not yet accepted

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions