package-repository

1 article
sort: new top best
clear filter
0 5/10
security-analysis

Daniel Stenberg documents persistent security failures in NuGet's package repository, where severely outdated curl versions (7.51.0 from 2016 with 64+ known vulnerabilities) continue to be hosted and downloaded thousands of times weekly. Microsoft MSRC refused responsibility, claiming package security is entirely the responsibility of individual package maintainers rather than the platform.

NuGet Microsoft curl rmt_curl Daniel Stenberg MSRC
daniel.haxx.se · HieronymusBosch · 16 hours ago · details · hn