Skip to content

elmahio/github-check-vulnerable-nuget-packages-action

Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

20 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Check vulnerable NuGet packages GitHub Action

This action will check for vulnerable NuGet packages in one or more projects/solutions. If vulnerable packages are found, they will be listed and the build will fail.

Screenshot

The code is based on this excellent blog post by Steven Giesel. Development of the action is sponsored by elmah.io.

Inputs

project

The project or solution file to operate on. If a file is not specified, the command will search current directory for one.

Example usage

Check all projects and solutions for vulnerable NuGet packages:

- name: Check vulnerable NuGet packages
  uses: elmahio/github-check-vulnerable-nuget-packages-action@v1

Check a specific project for vulnerable NuGet packages:

- name: Check vulnerable NuGet packages
  uses: elmahio/github-check-vulnerable-nuget-packages-action@v1
  with:
    project: 'src/HelloWorld.csproj'