Skip to content

Expand Audit to include diagnostic information about packages #46486

Open
@richlander

Description

@richlander

At present, Audit is focused on CVEs in NuGet packages. It should be expanded more broadly. This will undoubtably need to be described in a spec.

Here's some ideas to report on:

  • PackageRef lifts a package graph to a new major version
  • PackageRef is to non-latest package
  • PackageRef is to deprecated/unsupported packages
  • PackageRef is to package that hasn't been updated in n months/years.
  • TFM/target runtime is EOL
  • TFM/target runtime doesn't support current OS

Tracking issues:

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions