<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Vulnerability scanning]]></title><description><![CDATA[<p dir="auto">I am evaluating enterprise. Real detection engine, but its database doesn't fully overlap with NVD/Trivy, and its client-facing warnings are a periodic snapshot rather than real-time (re-verified). Live blocking, separately, is real-time.<br />
Coverage gap<br />
Microsoft.Build.Tasks.Core 17.7.2 → CVE-2025-26646 (HIGH per NVD, already known from our existing Trivy-based scanning) was not present at all in ProGet's database. Re-confirmed with the same isolated, ProGet-only source.</p>
]]></description><link>https://forums.inedo.com/topic/5834/vulnerability-scanning</link><generator>RSS for Node</generator><lastBuildDate>Tue, 15 Sep 2026 09:29:35 GMT</lastBuildDate><atom:link href="https://forums.inedo.com/topic/5834.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 14 Sep 2026 20:19:14 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Vulnerability scanning on Tue, 15 Sep 2026 09:11:43 GMT]]></title><description><![CDATA[<p dir="auto">Hi <a class="plugin-mentions-user plugin-mentions-a" href="/user/sai.pabbareddy" aria-label="Profile: sai.pabbareddy">@<bdi>sai.pabbareddy</bdi></a> ,</p>
<p dir="auto">I'm not really sure what question you're asking?</p>
<p dir="auto">CVE-2025-26646 has been in Inedo's database as <a href="https://security.inedo.com/vulnerability/details/PGV-2535204" rel="nofollow ugc">PGV-2535204</a> since  May 13, 2025.</p>
<p dir="auto">However, under the default risk profile in ProGet, we rate this a Category 1 since there is effectively no risk posed by this vulnerability. It requires a malicious inside actor with access to modify the source code -- which is not a realistic threat actor.</p>
<p dir="auto">As such, ProGet will not not "spam" developers via the NuGet client with needless warnings. This is all by design.</p>
<p dir="auto">You can learn more about that here: <a href="https://guides.inedo.com/vulnerability-management/categories/" rel="nofollow ugc">https://guides.inedo.com/vulnerability-management/categories/</a></p>
<p dir="auto">Thanks,<br />
Alana</p>
]]></description><link>https://forums.inedo.com/post/20026</link><guid isPermaLink="true">https://forums.inedo.com/post/20026</guid><dc:creator><![CDATA[atripp]]></dc:creator><pubDate>Tue, 15 Sep 2026 09:11:43 GMT</pubDate></item></channel></rss>