← cd ../projects
Completed client · BDO

BDO Transient Package Updater

A .NET tool that finds and fixes vulnerable transitive NuGet dependencies across codebases, then opens the pull requests automatically.

$ git log --author=casper

My contribution

  • Rebuilt the dependency analysis around a custom NuGet-based resolver that builds a fully resolved dependency tree (replacing the project.assets.json approach)
  • Added updating of .csproj and Central Package Management files
  • Brought a full scan down to about 30 seconds with caching, batching and parallelism
  • Owned the Azure DevOps pipeline end-to-end: it runs the tool against other repositories and creates the pull requests. The second version moved the commit/PR logic into the application itself
  • Wrote 21 of the 23 unit tests and set up SonarCloud static analysis

Dependency scanners like Mend/WhiteSource mostly flag vulnerabilities in direct dependencies. Packages pulled in indirectly through other libraries (transitive dependencies) stay largely invisible, even though they are just as risky.

What we built

For BDO we built a C# tool that:

  • resolves the complete dependency tree of a .NET application, direct and transitive
  • checks every package against vulnerability databases and reports clearly what's affected
  • updates vulnerable transitive packages automatically and opens pull requests, similar to Renovate or Dependabot

Running as a pipeline across repositories, it extends vulnerability management to the full dependency graph instead of just the top layer.

Process

We worked in Scrum sprints with a Definition of Done, a shared test plan, sprint retrospectives and weekly meetings with BDO, and finished with a final delivery presentation to the stakeholders.

Gallery

2 images

# How it works

  • Package A depends on C only indirectly, through B: that hidden link is where vulnerabilities slip through
  • The tool resolving a full dependency tree, flagging transitive and vulnerable packages