Cerbi.GovernanceAnalyzer
1.0.0
dotnet add package Cerbi.GovernanceAnalyzer --version 1.0.0
NuGet\Install-Package Cerbi.GovernanceAnalyzer -Version 1.0.0
<PackageReference Include="Cerbi.GovernanceAnalyzer" Version="1.0.0"> <PrivateAssets>all</PrivateAssets> <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets> </PackageReference>
<PackageVersion Include="Cerbi.GovernanceAnalyzer" Version="1.0.0" />
<PackageReference Include="Cerbi.GovernanceAnalyzer"> <PrivateAssets>all</PrivateAssets> <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets> </PackageReference>
paket add Cerbi.GovernanceAnalyzer --version 1.0.0
#r "nuget: Cerbi.GovernanceAnalyzer, 1.0.0"
#:package Cerbi.GovernanceAnalyzer@1.0.0
#addin nuget:?package=Cerbi.GovernanceAnalyzer&version=1.0.0
#tool nuget:?package=Cerbi.GovernanceAnalyzer&version=1.0.0
Cerbi.GovernanceAnalyzer
Universal Roslyn analyzer for compile-time log governance. Validates {Placeholder} message template fields against governance profiles for all major .NET logging frameworks:
- ✅ Microsoft.Extensions.Logging (ILogger)
- ✅ Serilog (ILogger, static Log)
- ✅ NLog (ILogger, Logger)
Why?
CerbiShield enforces log governance at runtime. This analyzer catches violations at compile time — before code even ships. Missing required fields, forbidden PII fields, type mismatches, and invalid enum values are flagged as build warnings/errors.
Installation
dotnet add package Cerbi.GovernanceAnalyzer
Setup
- Add the NuGet package to your project
- Create a
cerbi_governance.jsonfile in your project root - Reference it as an AdditionalFile in your
.csproj:
<ItemGroup>
<AdditionalFiles Include="cerbi_governance.json" />
</ItemGroup>
Governance Profile Example
{
"name": "PII-Protection",
"appName": "payment-service",
"requiredFields": ["userId", "correlationId"],
"disallowedFields": ["ssn", "creditCardNumber"],
"fieldSeverities": {
"userId": "Error",
"ssn": "Forbidden",
"debugInfo": "Warn"
},
"fieldTypes": {
"userId": "String",
"correlationId": "Guid",
"retryCount": "Int"
},
"enums": {
"environment": ["dev", "test", "staging", "production"]
},
"allowRelax": false
}
Diagnostics
| ID | Title | Severity | Description |
|---|---|---|---|
| CERBI000 | No profile loaded | Info | No cerbi_governance.json found in AdditionalFiles |
| CERBI001 | Missing required field | Error | A required field is not in the message template |
| CERBI002 | Forbidden field | Error | A disallowed field appears in the message template |
| CERBI003 | Advisory field | Warning | A field has advisory-level severity |
| CERBI004 | Invalid field type | Warning | Argument type doesn't match expected type |
| CERBI005 | Invalid enum value | Warning | String value not in allowed enum list |
How It Works
The analyzer runs inside the C# compiler (Roslyn). It:
- Loads
cerbi_governance.jsonfromAdditionalFilesat compilation start - Intercepts every logging method invocation (
LogInformation,Warning,Info, etc.) - Detects the logging framework via semantic model type checking
- Extracts
{Placeholder}field names from message templates - Validates fields against the governance profile rules
- Reports diagnostics as compiler warnings/errors
Zero runtime overhead — all analysis happens at build time only.
License
MIT
Learn more about Target Frameworks and .NET Standard.
This package has no dependencies.
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.0.0 | 227 | 3/17/2026 |