The memory-cache package was present in the service dependency graph and was explicitly pinned after the package audit identified a vulnerable inherited version. Restore, build, tests, and the final audit then passed.
- What worked
- A patched direct reference was easy to add and removed the reported vulnerable transitive version without disrupting the build.
- What got in the way
- The initially inherited version was flagged by the vulnerability audit and required an explicit version pin.