On this page
- Centralise NuGet versions and lock restore for release reproducibility.
- Generate SPDX or CycloneDX SBOMs in CI.
- Retain vulnerable-package review and exploitability decisions.
- Link signed artifacts, release notes, support policy, and corrective updates.
Make NuGet resolution reproducible
Use PackageReference with deliberate version management, commit packages.lock.json where appropriate, and run locked restores for release builds. Capture the SDK version through global.json or a controlled build image.
Add release security evidence
Run dependency vulnerability checks and relevant static or dynamic testing in CI. Preserve results with the release evidence instead of relying on transient logs.
Connect component findings to product impact
A NuGet advisory match is an input, not the final product conclusion. Record whether the vulnerable component and code path ship, whether the weakness is reachable, what versions are affected, and how customers receive the correction - the decisions vulnerability handling exists to capture.
Document product behaviour beyond the repository
Threat models, deployment architecture, remote service dependencies, user instructions, support-period commitments, incident decisions, and conformity materials may sit outside source control. Include them in the product evidence index.
Frequently asked questions
Does ConformOps replace .NET security tooling?
No. It can use evidence from dependency and security tools, then connect results to CRA readiness, remediation, and technical documentation.
Should we scan only direct NuGet packages?
No. Direct dependencies are important, but transitive dependencies and components in the actual published artifact also affect vulnerability handling and SBOM completeness.