Closed Bertk closed 2 years ago
Please use the nuget.org feature to mark vulnerable packages.
We use the following command in our CI build pipeline to break the build and some starkbank-ecdsa versions with CVE-2021-43569 are not detected.
dotnet list package --vulnerable --include-transitive --source https://api.nuget.org/v3/index.json
see How to Scan NuGet Packages for Security Vulnerabilities
Thank you for your fast response 👍
Please use the nuget.org feature to mark vulnerable packages.
We use the following command in our CI build pipeline to break the build and some starkbank-ecdsa versions with CVE-2021-43569 are not detected.
see How to Scan NuGet Packages for Security Vulnerabilities