Skip to main content
Microsoft
NuGet
NuGet
  • Home
  • DevBlogs
    • Azure DevOps
    • Notification Hubs
    • Visual Studio
    • Visual Studio Code
    • Visual Studio for Mac
    • Azure Artifacts
    • Azure Boards
    • Azure Pipelines
    • Azure Repos
    • Azure Test Plans
    • DevOps
    • C++
    • Java
    • Java Blog in Chinese
    • JavaScript
    • PowerShell Community
    • PowerShell Team
    • Python
    • Q#
    • TypeScript
    • Visual Basic
    • Visual C#
    • Visual F#
    • .NET
    • ASP.NET
    • NuGet
    • Xamarin
    • #ifdef Windows
    • Apps for Windows
    • Azure Depth Platform
    • Azure Government
    • Azure SDKs
    • Bing Dev Center
    • Command Line
    • CSE Developer
    • Developer Support
    • DirectX Developer Blog
    • IoT Developer
    • Math In Office
    • Microsoft Edge Dev
    • Microsoft Azure
    • Office 365 Development
    • Old New Thing
    • PAX Media
    • Perf and Diagnostics
    • PIX on Windows
    • Startup Developers
    • Surface Duo
    • Sustainable Software
    • Windows Search Platform
    • Azure Cosmos DB
    • Azure Data Studio
    • Azure SQL
    • Azure Synapse Analytics
    • OData
    • Revolutions R
    • SQL Server Data Tools

    The NuGet Blog

    The latest news, updates, and insights from the NuGet team

    Security Archives | The NuGet Blog

    How to Scan NuGet Packages for Security Vulnerabilities
    How to Scan NuGet Packages for Security Vulnerabilities
    Avatar drewgillies March 2, 2021 Mar 2, 2021 03/2/21
    Today, we are announcing the public availability of NuGet’s vulnerability features that you can use to ensure your projects are vulnerability free and if not, to take action to securing your software supply chain.

    11Feature AnnouncementNuGet
    The NuGet.org repository signing certificate will be updated as soon as March 15th, 2021
    The NuGet.org repository signing certificate will be updated as soon as March 15th, 2021
    Avatar Christopher Gill February 25, 2021 Feb 25, 2021 02/25/21
    The current NuGet.org repository signing certificate will be updated as soon as March 15th, 2021. If you validate that packages are repository signed by NuGet.org, you will need to take steps to avoid disruptions when installing packages from NuGet.org.

    1NuGetNuGet.org
    The Microsoft author signing certificate will be updated as soon as November 1st, 2020
    The Microsoft author signing certificate will be updated as soon as November 1st, 2020
    Avatar Christopher Gill October 22, 2020 Oct 22, 2020 10/22/20
    The current Microsoft author signing certificate will be updated as soon as November 1st, 2020. If you validate that packages are author signed by Microsoft, you will need to take steps to avoid disruptions when installing Microsoft packages.

    Comments are closed.0NuGetNuGet.org
    NuGet.org will permanently remove support for TLS 1.0 and 1.1 on June 15th
    NuGet.org will permanently remove support for TLS 1.0 and 1.1 on June 15th
    Avatar Christopher Gill May 25, 2020 May 25, 2020 05/25/20
    Last November, we shared our two-stage plan for deprecating TLS 1.0/1.1 on NuGet.org in which we stated that the permanent removal of TLS 1.0/1.1 support would occur in April 2020. However, in April, to avoid disrupting customers in the midst of the COVID-19 pandemic, we announced that we would continue to support TLS 1.0/1.1 until further ...

    Comments are closed.0NuGet.orgSecurity
    NuGet.org will continue to support TLS 1.0 and 1.1 until further notice
    NuGet.org will continue to support TLS 1.0 and 1.1 until further notice
    Avatar Christopher Gill April 22, 2020 Apr 22, 2020 04/22/20
    Last November, we shared our two-stage plan for deprecating TLS 1.0/1.1 on NuGet.org and actions you can take today to ensure your systems use TLS 1.2. In that post, we announced that NuGet.org would remove support for TLS 1.0/1.1 in April 2020. However, since then, our customers have faced a variety of challenges in the wake of the COVID-19 ...

    Comments are closed.0NuGet.orgOther announcements
    Deprecating TLS 1.0 and 1.1 on NuGet.org – Stage 1
    Deprecating TLS 1.0 and 1.1 on NuGet.org – Stage 1
    Avatar The NuGet Team February 12, 2020 Feb 12, 2020 02/12/20
    In this post, we will go into more details and a specific timeline for Stage 1 i.e. temporarily removing support for TLS 1.0/1.1 on NuGet.org. The goal is to help you identify systems that may be affected and will give you an opportunity to take action before we permanently remove support for TLS 1.0/1.1 in April 2020.

    Comments are closed.0NuGetNuGet.org
    Deprecating TLS 1.0 and 1.1 on NuGet.org
    Deprecating TLS 1.0 and 1.1 on NuGet.org
    Karan Nandwani Karan Nandwani November 15, 2019 Nov 15, 2019 11/15/19
    co-authored by Scott Bommarito At Microsoft, using the latest and secure encryption techniques is very important to us to ensure the security and privacy of our customers. TLS 1.0 and TLS 1.1, released in 1999 and 2006 respectively, are known to be vulnerable to a number of attacks including POODLE and BEAST. In the past, we removed ...

    Comments are closed.0NuGet.orgOther announcements
    Lock down your dependencies using configurable trust policies
    Lock down your dependencies using configurable trust policies
    Avatar Rido December 5, 2018 Dec 5, 2018 12/5/18
    For the past several months we have focused on various features to improve package security and trust. Around a year back, we had announced our plans on various signing functionalities that we have been implementing at a steady pace. We enabled package author signing and NuGet.org repository signing earlier this year. Continuing on the signing...

    Comments are closed.0Security
    NuGet.org starts repo-signing packages
    NuGet.org starts repo-signing packages
    Avatar Rido August 10, 2018 Aug 10, 2018 08/10/18
    In May, we implemented Stage 1 and enabled support for any NuGet.org user to submit signed packages to NuGet.org. Today, we are announcing Stage 2 of our NuGet package signing journey - tamper proofing the entire package dependency graph. What is a Repository Signature? A repository signature is a code signing signature produced with an X....

    Comments are closed.0NuGet.orgSecurity
    Introducing signed package submissions to NuGet.org
    Introducing signed package submissions to NuGet.org
    Avatar Rido May 22, 2018 May 22, 2018 05/22/18
    In September 2017, we announced our plans to improve the security of the NuGet ecosystem by introducing the ability for package authors to sign packages. Today, we want to announce support for any NuGet.org user to submit signed packages to NuGet.org. A signed NuGet package is designed to be fully compatible with pre-existing NuGet servers ...

    Comments are closed.0Feature AnnouncementNuGet.org
    • Page 1
    • Page 2
    • Next page
    Relevant Links

    NuGet.org

    NuGet documentation

    Release Notes

    Announcements

    Report a client bug

    Report a NuGet.org bug

    Topics
  • NuGet.org
  • Release announcement
  • Feature Announcement
  • Visual Studio
  • Other announcements
  • Security
  • Incident
  • NuGet
  • Roadmap
  • Insights
  • Debugging
  • Deprecation
  • Archive
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • August 2020
  • May 2020
  • April 2020
  • February 2020
  • November 2019
  • September 2019
  • August 2019
  • July 2019
  • April 2019
  • December 2018
  • November 2018
  • August 2018
  • July 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • September 2017
  • August 2017
  • July 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • November 2015
  • October 2015
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • March 2015
  • February 2015
  • December 2014
  • November 2014
  • October 2014
  • September 2014
  • August 2014
  • July 2014
  • June 2014
  • May 2014
  • April 2014
  • March 2014
  • December 2013
  • November 2013
  • October 2013
  • September 2013
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • December 2012
  • October 2012
  • September 2012
  • August 2012
  • June 2012
  • May 2012
  • April 2012
  • March 2012
  • Stay informed

    Login
    Code Block
    What's new
    • Surface Duo
    • Surface Laptop Go
    • Surface Pro X
    • Surface Go 2
    • Surface Book 3
    • Microsoft 365
    • Windows 10 apps
    • HoloLens 2
    Microsoft Store
    • Account profile
    • Download Center
    • Microsoft Store support
    • Returns
    • Order tracking
    • Virtual workshops and training
    • Microsoft Store Promise
    • Financing
    Education
    • Microsoft in education
    • Office for students
    • Office 365 for schools
    • Deals for students & parents
    • Microsoft Azure in education
    Enterprise
    • Azure
    • AppSource
    • Automotive
    • Government
    • Healthcare
    • Manufacturing
    • Financial services
    • Retail
    Developer
    • Microsoft Visual Studio
    • Windows Dev Center
    • Developer Center
    • Microsoft developer program
    • Channel 9
    • Microsoft 365 Dev Center
    • Microsoft 365 Developer Program
    • Microsoft Garage
    Company
    • Careers
    • About Microsoft
    • Company news
    • Privacy at Microsoft
    • Investors
    • Diversity and inclusion
    • Accessibility
    • Security
    English (United States)
    • Sitemap
    • Contact Microsoft
    • Privacy
    • Manage cookies
    • Terms of use
    • Trademarks
    • Safety & eco
    • About our ads
    • © Microsoft 2021