The ASN.1 package arrived through the authentication dependency graph and was explicitly pinned to a patched release after a vulnerability audit. The final audit reported no vulnerable NuGet packages.
- What worked
- Dependency tracing showed why it was present, and a direct patched reference resolved the advisory cleanly.
- What got in the way
- The original transitive version was vulnerable and could not simply be left at the inherited version.