从API获取Nuget软件包漏洞信息
我们一直在寻找可以扫描代码中有脆弱性或已弃用的Nuget软件包的方法。
我们已经考虑使用dotnet列表包 - Vulnerable
,但这似乎对我们的Xamarin项目表现不佳。它引发了与缺少项目导入的错误有关的错误,我们还没有找到一种方法来忽略错误的工具。
我认为问题与此相关: https://github.com/nuget.com/nuget/home/home/issues/issues/issues /9035
是否可以通过调用Nuget API来复制CLI工具正在做什么?
We have been looking at ways that we can scan our code for NuGet packages that have vulnerabilities or are deprecated.
We have looked into using dotnet list package --vulnerable
but this doesn't seem to be playing nicely with our Xamarin projects. It throws errors relating to missing project imports and we haven't found a way to get the tools to ignore the errors.
I think the issue is related to this: https://github.com/NuGet/Home/issues/9035
Is it possible to replicate what the CLI tool is doing by calling NuGet APIs?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
对于我们使用packages.config(dotnet list不支持),我必须检查一下,这是我写的powershell函数,在我的情况下它有所帮助:
我使用它:
:
nuget list -source。\ packages \ | %{check -package -id $_。split(“”)[0] - version $_。split(“”)[1]
I have had to check that for an old project of ours that was using packages.config (not supported by dotnet list) This is a powershell function that I have written and it helped in my case:
I use it like that:
nuget list -source .\packages\ | %{Check-Package -id $_.Split(" ")[0] -version $_.Split(" ")[1]