Completed client · BDO
BDO Transient Package Updater
A .NET tool that finds and fixes vulnerable transitive NuGet dependencies across codebases, then opens the pull requests automatically.
$ git log --author=casper
My contribution
- Rebuilt the dependency analysis around a custom NuGet-based resolver that builds a fully resolved dependency tree (replacing the
project.assets.jsonapproach) - Added updating of
.csprojand Central Package Management files - Brought a full scan down to about 30 seconds with caching, batching and parallelism
- Owned the Azure DevOps pipeline end-to-end: it runs the tool against other repositories and creates the pull requests. The second version moved the commit/PR logic into the application itself
- Wrote 21 of the 23 unit tests and set up SonarCloud static analysis
Dependency scanners like Mend/WhiteSource mostly flag vulnerabilities in direct dependencies. Packages pulled in indirectly through other libraries (transitive dependencies) stay largely invisible, even though they are just as risky.
What we built
For BDO we built a C# tool that:
- resolves the complete dependency tree of a .NET application, direct and transitive
- checks every package against vulnerability databases and reports clearly what's affected
- updates vulnerable transitive packages automatically and opens pull requests, similar to Renovate or Dependabot
Running as a pipeline across repositories, it extends vulnerability management to the full dependency graph instead of just the top layer.
Process
We worked in Scrum sprints with a Definition of Done, a shared test plan, sprint retrospectives and weekly meetings with BDO, and finished with a final delivery presentation to the stakeholders.
Gallery
2 images# How it works
Package A depends on C only indirectly, through B: that hidden link is where vulnerabilities slip through The tool resolving a full dependency tree, flagging transitive and vulnerable packages