Hi @joacim-svensson_8194 ,
That should have worked, but it's of course possible there's a bug.
Can you confirm steps?
Is this basically what you did?
Create Two feeds (Feed1 and Feed2), download a vulnerable package in each feed
Create Two Vuln Sources (OssIndex1, OssIndex2), associate each to each feed
Run the "Vuln Downloader" Job, and see two identical vulnerabilities added to ProGet
Assess the vulnerabilities differently (1 = Block, 2= Ignore)
Package should Blocked on Feed1, and allowed on Feed2
I want to make sure we're following the steps you did, so we can test this.
Cheers,
Steve