DotnetAuditLite 1.0.1
dotnet tool install --global DotnetAuditLite --version 1.0.1
dotnet new tool-manifest
dotnet tool install --local DotnetAuditLite --version 1.0.1
#tool dotnet:?package=DotnetAuditLite&version=1.0.1
nuke :add-package DotnetAuditLite --version 1.0.1
DotnetAudit Lite
Local-first .NET repository preflight that creates readable Markdown and SARIF 2.1.0 without uploading source code to an external service.
Install as a .NET tool
DotnetAuditLite 1.0.1 is published on
NuGet.org. Install it
globally with:
dotnet tool install --global DotnetAuditLite
dotnet-audit-lite --path .
To install into an isolated directory instead:
dotnet tool install DotnetAuditLite --tool-path ./.tools --version 1.0.1
./.tools/dotnet-audit-lite --path . --static-only
The tool runs with the current user's permissions. Review the repository and
package before installation, and use --static-only when the target repository
must not execute build or test commands.
Use as a GitHub Action
Install from GitHub Marketplace or add the Action directly:
- uses: Dalkory/DotnetAuditLite@v1
What it checks
- target frameworks and an embedded .NET 8/9/10 support snapshot;
Nullableand warnings-as-errors settings;- common CI, Docker, health-check and OpenTelemetry signals;
- sensitive-looking files and assignments without printing detected values;
- optional local
dotnet build,dotnet testand vulnerable-package checks.
Complete workflow
name: .NET preflight
on:
workflow_dispatch:
push:
branches: [main]
permissions:
contents: read
security-events: write
jobs:
preflight:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: Dalkory/DotnetAuditLite@v1
with:
path: .
output: dotnet-preflight-report.md
sarif-output: dotnet-preflight.sarif
- uses: actions/upload-artifact@v4
with:
name: dotnet-preflight-report
path: dotnet-preflight-report.md
- uses: github/codeql-action/upload-sarif@v4
with:
sarif_file: dotnet-preflight.sarif
category: dotnet-audit-lite
The Action performs a static preflight. It writes both files but does not upload them by itself, so teams can use only the local Markdown artifact if they do not want Code Scanning.
Run from source
Requirements: .NET 8 SDK or newer.
dotnet run --project DotnetAuditLite.csproj -- `
--path C:\path\to\repository `
--output dotnet-preflight-report.md `
--sarif dotnet-preflight.sarif
For a scan that never executes the target repository:
dotnet run --project DotnetAuditLite.csproj -- --path C:\path\to\repository --static-only
The lifecycle snapshot follows the official Microsoft .NET support policy as of 2026-07-27. Future framework versions are marked for manual verification instead of being guessed.
Example result
# DotnetAudit Lite — preflight report
Projects discovered: 4
Findings: 7
HIGH net6.0: out of support
MEDIUM No health-check wiring detected
MEDIUM No OpenTelemetry wiring detected
LOW Warnings are not explicitly treated as errors
The sample consumer repository shows the Action, downloadable Markdown artifact and Code Scanning integration: https://github.com/Dalkory/DotnetAuditLiteSample
Limitations
- This is a signal-oriented pre-check, not proof of production readiness.
- Secret matching is intentionally conservative and never prints detected values.
- Static checks cannot prove runtime reliability, authorization correctness or regulatory compliance.
- SARIF upload works for public repositories; private repositories need the applicable GitHub Code Security plan and settings.
- Findings must be reviewed before sharing them outside the repository owner’s organization.
Paid interpretation
Want priorities instead of a raw report? Open Request paid interpretation with only non-confidential context. A fixed-scope human review can turn the preflight into a one-problem diagnosis, AI Repo Enablement, modernization assessment or remediation plan.
Formats and contact: https://dotnet-audit-studio.dtauskanov3.chatgpt.site/en
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
This package has no dependencies.