Today is also two years since "the nuget story" where I struggled to get a ten year old and vulnerable #curl version delisted:
https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/
Today is also two years since "the nuget story" where I struggled to get a ten year old and vulnerable #curl version delisted:
https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/
@bagder sadly this is an issue with all those package repositories, not just nuget. You have to be careful what packages you use, and also monitor whether they actually get updated when needed.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.