So Microsoft Deleted Some of Our Packages From NuGet.org Without Notice
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Microsoft deleted NuGet packages from third-party developers without notice to address a security vulnerability in their Microsoft.Identity.Client package. The vulnerability was a typo in XML documentation pointing to a phishing URL, not a critical runtime issue. This action bypassed normal CVE disclosure processes and created concerns about package availability guarantees, Microsoft's privileged access to NuGet operations, and the arbitrary nature of the deletions. The incident highlights tensions between security remediation and package ecosystem stability.
Table of contents
An uncomfortable precedent that should not be repeated - even for CVEs.Microsoft.Identity.Client Security VulnerabilitiesA Bad PrecedentSort: