Skip to content

Direct Dependencies can use Audit Sources in PM UI - #6806

Merged
donnie-msft merged 1 commit into
devfrom
dev-donnie-msft-pmuiAuditDirect
Sep 26, 2025
Merged

donnie-msft merged 1 commit into
devfrom
dev-donnie-msft-pmuiAuditDirect

Conversation

@donnie-msft

@donnie-msft donnie-msft commented Sep 26, 2025 •

Copy link
Copy Markdown
Contributor

Bug

Fixes: https://github.com/NuGet/Client.Engineering/issues/3435

Description

Direct dependencies in PM UI were using a VulnerablePackageMetadataCapability in the package model. The model instead needs to leverage the vulnerability service so that either the vulnerability data from the Package Source resources can be used, or the Audit Source, if configured.

image

Validation

  • All existing unit tests still pass.
  • Validated nuget.org as a package source, a Top-Level & Transitive dependency both reflect vulnerabilities
  • Validated nuget.org as an Audit source (only), a Top-Level & Transitive dependency both reflect vulnerabilities
  • Validated that with no vulnerability resource (eg, here I removed nuget.org entirely), the PM UI renders the Installed packages with no vulnerability data.

PR Checklist

  • Meaningful title, helpful description and a linked NuGet/Home issue
  • Added tests
  • Link to an issue or pull request to update docs if this PR changes settings, environment variables, new feature, etc.

@donnie-msft
donnie-msft requested a review from a team as a code owner September 26, 2025 05:28
@donnie-msft donnie-msft changed the title Direct Dependencies use Audit Sources in PM UI Direct Dependencies can use Audit Sources in PM UI Sep 26, 2025
@donnie-msft
donnie-msft merged commit 3ca8733 into dev Sep 26, 2025
17 of 18 checks passed
@donnie-msft
donnie-msft deleted the dev-donnie-msft-pmuiAuditDirect branch September 26, 2025 19:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants