Skip to content

Conversation

@nkolev92
Copy link
Member

@nkolev92 nkolev92 commented Oct 23, 2025

I tried to get copilot to do it, but it incorrectly assumed that all the content was actually include, but the instruction for the transitive paths wasn't.

Anyway, this PR is a start and we can iterate more.

Fixes: NuGet/Home#14612

@nkolev92 nkolev92 requested a review from a team as a code owner October 23, 2025 23:58
Copilot AI review requested due to automatic review settings October 23, 2025 23:58
@nkolev92 nkolev92 requested a review from a team as a code owner October 23, 2025 23:58
@nkolev92 nkolev92 requested a review from zivkan October 23, 2025 23:58
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR moves guidance from a blog post into the official documentation for handling packages with known vulnerabilities. The changes update references to point to the new documentation location and expand the content with detailed instructions for resolving vulnerabilities in both direct and transitive package dependencies.

Key Changes:

  • Replaced blog post references with links to expanded documentation
  • Added comprehensive guidance on handling transitive package vulnerabilities
  • Added instructions and screenshots for three methods to find transitive package paths

Reviewed Changes

Copilot reviewed 2 out of 6 changed files in this pull request and generated 3 comments.

File Description
docs/reference/errors-and-warnings/NU1901-NU1904.md Updated reference from blog post to new documentation section
docs/concepts/Auditing-Packages.md Added detailed guidance on resolving vulnerabilities and finding transitive package paths, with visual examples

@learn-build-service-prod
Copy link

PoliCheck Scan Report

The following report lists PoliCheck issues in PR files. Before you merge the PR, you must fix all severity-1 issues. Other issues are also a high priority. The AI Review Details column lists suggestions for either removing or replacing the terms. If you find a false positive result, mention it in a PR comment and include this text: #policheck-false-positive. This feedback helps reduce false positives in future scans.

✅ No issues found

More information about PoliCheck

Information: PoliCheck | Severity Guidance | Term
For any questions: Try searching the learn.microsoft.com contributor guides or post your question in the Learn support channel.

@learn-build-service-prod
Copy link

Learn Build status updates of commit 848d388:

💡 Validation status: suggestions

File Status Preview URL Details
docs/concepts/media/pmui-transitive-tooltip-1.png 💡Suggestion View Details
docs/concepts/Auditing-Packages.md ✅Succeeded View
docs/concepts/media/dotnet-nuget-why-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-options-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-results-1.png ✅Succeeded View
docs/reference/errors-and-warnings/NU1901-NU1904.md ✅Succeeded View

docs/concepts/media/pmui-transitive-tooltip-1.png

  • Line 0, Column 0: [Suggestion: image-name-incomplete - See documentation] The image name contains an incomplete word, misspelled word, acronym, or abbreviation that is disallowed.

For more details, please refer to the build report.

Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them.

@nkolev92 nkolev92 requested a review from Copilot October 24, 2025 00:00
@learn-build-service-prod
Copy link

PoliCheck Scan Report

The following report lists PoliCheck issues in PR files. Before you merge the PR, you must fix all severity-1 issues. Other issues are also a high priority. The AI Review Details column lists suggestions for either removing or replacing the terms. If you find a false positive result, mention it in a PR comment and include this text: #policheck-false-positive. This feedback helps reduce false positives in future scans.

✅ No issues found

More information about PoliCheck

Information: PoliCheck | Severity Guidance | Term
For any questions: Try searching the learn.microsoft.com contributor guides or post your question in the Learn support channel.

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Copilot reviewed 2 out of 6 changed files in this pull request and generated 1 comment.

@learn-build-service-prod
Copy link

Learn Build status updates of commit 6dd8399:

💡 Validation status: suggestions

File Status Preview URL Details
docs/concepts/media/pmui-transitive-tooltip-1.png 💡Suggestion View Details
docs/concepts/Auditing-Packages.md ✅Succeeded View
docs/concepts/media/dotnet-nuget-why-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-options-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-results-1.png ✅Succeeded View
docs/reference/errors-and-warnings/NU1901-NU1904.md ✅Succeeded View

docs/concepts/media/pmui-transitive-tooltip-1.png

  • Line 0, Column 0: [Suggestion: image-name-incomplete - See documentation] The image name contains an incomplete word, misspelled word, acronym, or abbreviation that is disallowed.

For more details, please refer to the build report.

Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them.

@learn-build-service-prod
Copy link

PoliCheck Scan Report

The following report lists PoliCheck issues in PR files. Before you merge the PR, you must fix all severity-1 issues. Other issues are also a high priority. The AI Review Details column lists suggestions for either removing or replacing the terms. If you find a false positive result, mention it in a PR comment and include this text: #policheck-false-positive. This feedback helps reduce false positives in future scans.

✅ No issues found

More information about PoliCheck

Information: PoliCheck | Severity Guidance | Term
For any questions: Try searching the learn.microsoft.com contributor guides or post your question in the Learn support channel.

@learn-build-service-prod
Copy link

Learn Build status updates of commit 42d66ea:

💡 Validation status: suggestions

File Status Preview URL Details
docs/concepts/media/pmui-transitive-tooltip-1.png 💡Suggestion View Details
docs/concepts/Auditing-Packages.md ✅Succeeded View
docs/concepts/media/dotnet-nuget-why-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-options-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-results-1.png ✅Succeeded View
docs/reference/errors-and-warnings/NU1901-NU1904.md ✅Succeeded View

docs/concepts/media/pmui-transitive-tooltip-1.png

  • Line 0, Column 0: [Suggestion: image-name-incomplete - See documentation] The image name contains an incomplete word, misspelled word, acronym, or abbreviation that is disallowed.

For more details, please refer to the build report.

Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them.

@learn-build-service-prod
Copy link

PoliCheck Scan Report

The following report lists PoliCheck issues in PR files. Before you merge the PR, you must fix all severity-1 issues. Other issues are also a high priority. The AI Review Details column lists suggestions for either removing or replacing the terms. If you find a false positive result, mention it in a PR comment and include this text: #policheck-false-positive. This feedback helps reduce false positives in future scans.

✅ No issues found

More information about PoliCheck

Information: PoliCheck | Severity Guidance | Term
For any questions: Try searching the learn.microsoft.com contributor guides or post your question in the Learn support channel.

@learn-build-service-prod
Copy link

Learn Build status updates of commit 7af8fa8:

💡 Validation status: suggestions

File Status Preview URL Details
docs/concepts/media/pmui-transitive-tooltip-1.png 💡Suggestion View Details
docs/concepts/Auditing-Packages.md ✅Succeeded View
docs/concepts/media/dotnet-nuget-why-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-options-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-results-1.png ✅Succeeded View
docs/reference/errors-and-warnings/NU1901-NU1904.md ✅Succeeded View

docs/concepts/media/pmui-transitive-tooltip-1.png

  • Line 0, Column 0: [Suggestion: image-name-incomplete - See documentation] The image name contains an incomplete word, misspelled word, acronym, or abbreviation that is disallowed.

For more details, please refer to the build report.

Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them.

@nkolev92 nkolev92 requested a review from Copilot October 24, 2025 00:04
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Copilot reviewed 2 out of 6 changed files in this pull request and generated 3 comments.

@learn-build-service-prod
Copy link

PoliCheck Scan Report

The following report lists PoliCheck issues in PR files. Before you merge the PR, you must fix all severity-1 issues. Other issues are also a high priority. The AI Review Details column lists suggestions for either removing or replacing the terms. If you find a false positive result, mention it in a PR comment and include this text: #policheck-false-positive. This feedback helps reduce false positives in future scans.

✅ No issues found

More information about PoliCheck

Information: PoliCheck | Severity Guidance | Term
For any questions: Try searching the learn.microsoft.com contributor guides or post your question in the Learn support channel.

@learn-build-service-prod
Copy link

Learn Build status updates of commit 8ed6c58:

✅ Validation status: passed

File Status Preview URL Details
docs/concepts/Auditing-Packages.md ✅Succeeded View
docs/concepts/media/dotnet-nuget-why-1.png ✅Succeeded View
docs/concepts/media/pm-ui-transitive-tooltip-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-options-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-results-1.png ✅Succeeded View
docs/reference/errors-and-warnings/NU1901-NU1904.md ✅Succeeded View

For more details, please refer to the build report.

@nkolev92 nkolev92 requested a review from Copilot October 24, 2025 00:06
@learn-build-service-prod
Copy link

PoliCheck Scan Report

The following report lists PoliCheck issues in PR files. Before you merge the PR, you must fix all severity-1 issues. Other issues are also a high priority. The AI Review Details column lists suggestions for either removing or replacing the terms. If you find a false positive result, mention it in a PR comment and include this text: #policheck-false-positive. This feedback helps reduce false positives in future scans.

✅ No issues found

More information about PoliCheck

Information: PoliCheck | Severity Guidance | Term
For any questions: Try searching the learn.microsoft.com contributor guides or post your question in the Learn support channel.

@learn-build-service-prod
Copy link

Learn Build status updates of commit 2c7be46:

✅ Validation status: passed

File Status Preview URL Details
docs/concepts/Auditing-Packages.md ✅Succeeded View
docs/concepts/media/dotnet-nuget-why-1.png ✅Succeeded View
docs/concepts/media/pm-ui-transitive-tooltip-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-options-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-results-1.png ✅Succeeded View
docs/reference/errors-and-warnings/NU1901-NU1904.md ✅Succeeded View

For more details, please refer to the build report.

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Copilot reviewed 2 out of 6 changed files in this pull request and generated 4 comments.

@learn-build-service-prod
Copy link

Learn Build status updates of commit a822667:

✅ Validation status: passed

File Status Preview URL Details
docs/concepts/Auditing-Packages.md ✅Succeeded View
docs/concepts/media/dotnet-nuget-why-1.png ✅Succeeded View
docs/concepts/media/pm-ui-transitive-tooltip-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-options-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-results-1.png ✅Succeeded View
docs/reference/errors-and-warnings/NU1901-NU1904.md ✅Succeeded View

For more details, please refer to the build report.

@learn-build-service-prod
Copy link

PoliCheck Scan Report

The following report lists PoliCheck issues in PR files. Before you merge the PR, you must fix all severity-1 issues. Other issues are also a high priority. The AI Review Details column lists suggestions for either removing or replacing the terms. If you find a false positive result, mention it in a PR comment and include this text: #policheck-false-positive. This feedback helps reduce false positives in future scans.

✅ No issues found

More information about PoliCheck

Information: PoliCheck | Severity Guidance | Term
For any questions: Try searching the learn.microsoft.com contributor guides or post your question in the Learn support channel.

@learn-build-service-prod
Copy link

Learn Build status updates of commit 8a578ca:

✅ Validation status: passed

File Status Preview URL Details
docs/concepts/Auditing-Packages.md ✅Succeeded View
docs/concepts/media/dotnet-nuget-why-1.png ✅Succeeded View
docs/concepts/media/pm-ui-transitive-tooltip-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-options-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-results-1.png ✅Succeeded View
docs/reference/errors-and-warnings/NU1901-NU1904.md ✅Succeeded View

For more details, please refer to the build report.

@learn-build-service-prod
Copy link

PoliCheck Scan Report

The following report lists PoliCheck issues in PR files. Before you merge the PR, you must fix all severity-1 issues. Other issues are also a high priority. The AI Review Details column lists suggestions for either removing or replacing the terms. If you find a false positive result, mention it in a PR comment and include this text: #policheck-false-positive. This feedback helps reduce false positives in future scans.

✅ No issues found

More information about PoliCheck

Information: PoliCheck | Severity Guidance | Term
For any questions: Try searching the learn.microsoft.com contributor guides or post your question in the Learn support channel.

@nkolev92 nkolev92 requested review from Copilot and zivkan October 24, 2025 17:25
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Copilot reviewed 2 out of 6 changed files in this pull request and generated 1 comment.

@nkolev92 nkolev92 changed the title Move the blog post guidance to the docs Add updating vulnerable packages guidance to the docs Oct 24, 2025
@learn-build-service-prod
Copy link

PoliCheck Scan Report

The following report lists PoliCheck issues in PR files. Before you merge the PR, you must fix all severity-1 issues. Other issues are also a high priority. The AI Review Details column lists suggestions for either removing or replacing the terms. If you find a false positive result, mention it in a PR comment and include this text: #policheck-false-positive. This feedback helps reduce false positives in future scans.

✅ No issues found

More information about PoliCheck

Information: PoliCheck | Severity Guidance | Term
For any questions: Try searching the learn.microsoft.com contributor guides or post your question in the Learn support channel.

@learn-build-service-prod
Copy link

Learn Build status updates of commit 6634758:

✅ Validation status: passed

File Status Preview URL Details
docs/concepts/Auditing-Packages.md ✅Succeeded View
docs/concepts/media/dotnet-nuget-why-1.png ✅Succeeded View
docs/concepts/media/pm-ui-transitive-tooltip-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-options-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-results-1.png ✅Succeeded View
docs/reference/errors-and-warnings/NU1901-NU1904.md ✅Succeeded View

For more details, please refer to the build report.

@nkolev92 nkolev92 enabled auto-merge (squash) October 24, 2025 17:31
@learn-build-service-prod
Copy link

Learn Build status updates of commit bf149c4:

✅ Validation status: passed

File Status Preview URL Details
docs/concepts/Auditing-Packages.md ✅Succeeded View
docs/concepts/media/dotnet-nuget-why-1.png ✅Succeeded View
docs/concepts/media/pm-ui-transitive-tooltip-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-options-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-results-1.png ✅Succeeded View
docs/reference/errors-and-warnings/NU1901-NU1904.md ✅Succeeded View

For more details, please refer to the build report.

@nkolev92 nkolev92 requested a review from Copilot October 27, 2025 18:55
@learn-build-service-prod
Copy link

PoliCheck Scan Report

The following report lists PoliCheck issues in PR files. Before you merge the PR, you must fix all severity-1 issues. Other issues are also a high priority. The AI Review Details column lists suggestions for either removing or replacing the terms. If you find a false positive result, mention it in a PR comment and include this text: #policheck-false-positive. This feedback helps reduce false positives in future scans.

✅ No issues found

More information about PoliCheck

Information: PoliCheck | Severity Guidance | Term
For any questions: Try searching the learn.microsoft.com contributor guides or post your question in the Learn support channel.

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Copilot reviewed 2 out of 6 changed files in this pull request and generated 3 comments.

@learn-build-service-prod
Copy link

Learn Build status updates of commit 8727cf4:

⚠️ Validation status: warnings

File Status Preview URL Details
docs/concepts/Auditing-Packages.md ⚠️Warning View Details
docs/concepts/media/dotnet-nuget-why-1.png ✅Succeeded View
docs/concepts/media/pm-ui-transitive-tooltip-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-options-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-results-1.png ✅Succeeded View
docs/reference/errors-and-warnings/NU1901-NU1904.md ✅Succeeded View

docs/concepts/Auditing-Packages.md

  • Line 28, Column 160: [Warning: bookmark-not-found - See documentation] Cannot find bookmark '#security-vulnerabilities-found-with-updates' in 'concepts/Auditing-Packages.md'.
  • Line 190, Column 1: [Warning: code-block-unclosed - See documentation] Unclosed code block. Code blocks must begin and end with triple backticks (```).

For more details, please refer to the build report.

Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them.

@learn-build-service-prod
Copy link

PoliCheck Scan Report

The following report lists PoliCheck issues in PR files. Before you merge the PR, you must fix all severity-1 issues. Other issues are also a high priority. The AI Review Details column lists suggestions for either removing or replacing the terms. If you find a false positive result, mention it in a PR comment and include this text: #policheck-false-positive. This feedback helps reduce false positives in future scans.

✅ No issues found

More information about PoliCheck

Information: PoliCheck | Severity Guidance | Term
For any questions: Try searching the learn.microsoft.com contributor guides or post your question in the Learn support channel.

@learn-build-service-prod
Copy link

Learn Build status updates of commit 803984c:

⚠️ Validation status: warnings

File Status Preview URL Details
docs/concepts/Auditing-Packages.md ⚠️Warning View Details
docs/concepts/media/dotnet-nuget-why-1.png ✅Succeeded View
docs/concepts/media/pm-ui-transitive-tooltip-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-options-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-results-1.png ✅Succeeded View
docs/reference/errors-and-warnings/NU1901-NU1904.md ✅Succeeded View

docs/concepts/Auditing-Packages.md

  • Line 28, Column 160: [Warning: bookmark-not-found - See documentation] Cannot find bookmark '#security-vulnerabilities-found-with-updates' in 'concepts/Auditing-Packages.md'.
  • Line 190, Column 1: [Warning: code-block-unclosed - See documentation] Unclosed code block. Code blocks must begin and end with triple backticks (```).

For more details, please refer to the build report.

Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them.

@learn-build-service-prod
Copy link

PoliCheck Scan Report

The following report lists PoliCheck issues in PR files. Before you merge the PR, you must fix all severity-1 issues. Other issues are also a high priority. The AI Review Details column lists suggestions for either removing or replacing the terms. If you find a false positive result, mention it in a PR comment and include this text: #policheck-false-positive. This feedback helps reduce false positives in future scans.

✅ No issues found

More information about PoliCheck

Information: PoliCheck | Severity Guidance | Term
For any questions: Try searching the learn.microsoft.com contributor guides or post your question in the Learn support channel.

@learn-build-service-prod
Copy link

Learn Build status updates of commit c4c54c4:

✅ Validation status: passed

File Status Preview URL Details
docs/concepts/Auditing-Packages.md ✅Succeeded View
docs/concepts/media/dotnet-nuget-why-1.png ✅Succeeded View
docs/concepts/media/pm-ui-transitive-tooltip-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-options-1.png ✅Succeeded View
docs/concepts/media/vs-solution-explorer-search-results-1.png ✅Succeeded View
docs/reference/errors-and-warnings/NU1901-NU1904.md ✅Succeeded View

For more details, please refer to the build report.

@nkolev92 nkolev92 requested a review from a team October 27, 2025 19:59
Copy link
Contributor

@jebriede jebriede left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great guidance on updating vulnerable packages. I left one minor suggestion.

@nkolev92 nkolev92 merged commit 920c2a2 into main Nov 3, 2025
3 checks passed
@nkolev92 nkolev92 deleted the dev-nkolev92-migrate-blog-post-guiidance-into-docs branch November 3, 2025 22:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Remove the link from the auditing docs to the blog post for audit 2.0

4 participants