Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.
If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!
Vulnerability scanning
-
I am evaluating enterprise. Real detection engine, but its database doesn't fully overlap with NVD/Trivy, and its client-facing warnings are a periodic snapshot rather than real-time (re-verified). Live blocking, separately, is real-time.
Coverage gap
Microsoft.Build.Tasks.Core 17.7.2 → CVE-2025-26646 (HIGH per NVD, already known from our existing Trivy-based scanning) was not present at all in ProGet's database. Re-confirmed with the same isolated, ProGet-only source. -
Hi @sai.pabbareddy ,
I'm not really sure what question you're asking?
CVE-2025-26646 has been in Inedo's database as PGV-2535204 since May 13, 2025.
However, under the default risk profile in ProGet, we rate this a Category 1 since there is effectively no risk posed by this vulnerability. It requires a malicious inside actor with access to modify the source code -- which is not a realistic threat actor.
As such, ProGet will not not "spam" developers via the NuGet client with needless warnings. This is all by design.
You can learn more about that here: https://guides.inedo.com/vulnerability-management/categories/
Thanks,
Alana
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login