DotnetAuditLite 1.0.1

dotnet tool install --global DotnetAuditLite --version 1.0.1
                    
This package contains a .NET tool you can call from the shell/command line.
dotnet new tool-manifest
                    
if you are setting up this repo
dotnet tool install --local DotnetAuditLite --version 1.0.1
                    
This package contains a .NET tool you can call from the shell/command line.
#tool dotnet:?package=DotnetAuditLite&version=1.0.1
                    
nuke :add-package DotnetAuditLite --version 1.0.1
                    

DotnetAudit Lite

self-test release GitHub Marketplace

Local-first .NET repository preflight that creates readable Markdown and SARIF 2.1.0 without uploading source code to an external service.

Install as a .NET tool

DotnetAuditLite 1.0.1 is published on NuGet.org. Install it globally with:

dotnet tool install --global DotnetAuditLite
dotnet-audit-lite --path .

To install into an isolated directory instead:

dotnet tool install DotnetAuditLite --tool-path ./.tools --version 1.0.1
./.tools/dotnet-audit-lite --path . --static-only

The tool runs with the current user's permissions. Review the repository and package before installation, and use --static-only when the target repository must not execute build or test commands.

Use as a GitHub Action

Install from GitHub Marketplace or add the Action directly:

- uses: Dalkory/DotnetAuditLite@v1

DotnetAudit Lite report preview

What it checks

  • target frameworks and an embedded .NET 8/9/10 support snapshot;
  • Nullable and warnings-as-errors settings;
  • common CI, Docker, health-check and OpenTelemetry signals;
  • sensitive-looking files and assignments without printing detected values;
  • optional local dotnet build, dotnet test and vulnerable-package checks.

Complete workflow

name: .NET preflight

on:
  workflow_dispatch:
  push:
    branches: [main]

permissions:
  contents: read
  security-events: write

jobs:
  preflight:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - uses: Dalkory/DotnetAuditLite@v1
        with:
          path: .
          output: dotnet-preflight-report.md
          sarif-output: dotnet-preflight.sarif

      - uses: actions/upload-artifact@v4
        with:
          name: dotnet-preflight-report
          path: dotnet-preflight-report.md

      - uses: github/codeql-action/upload-sarif@v4
        with:
          sarif_file: dotnet-preflight.sarif
          category: dotnet-audit-lite

The Action performs a static preflight. It writes both files but does not upload them by itself, so teams can use only the local Markdown artifact if they do not want Code Scanning.

Run from source

Requirements: .NET 8 SDK or newer.

dotnet run --project DotnetAuditLite.csproj -- `
  --path C:\path\to\repository `
  --output dotnet-preflight-report.md `
  --sarif dotnet-preflight.sarif

For a scan that never executes the target repository:

dotnet run --project DotnetAuditLite.csproj -- --path C:\path\to\repository --static-only

The lifecycle snapshot follows the official Microsoft .NET support policy as of 2026-07-27. Future framework versions are marked for manual verification instead of being guessed.

Example result

# DotnetAudit Lite — preflight report

Projects discovered: 4
Findings: 7

HIGH    net6.0: out of support
MEDIUM  No health-check wiring detected
MEDIUM  No OpenTelemetry wiring detected
LOW     Warnings are not explicitly treated as errors

The sample consumer repository shows the Action, downloadable Markdown artifact and Code Scanning integration: https://github.com/Dalkory/DotnetAuditLiteSample

Limitations

  • This is a signal-oriented pre-check, not proof of production readiness.
  • Secret matching is intentionally conservative and never prints detected values.
  • Static checks cannot prove runtime reliability, authorization correctness or regulatory compliance.
  • SARIF upload works for public repositories; private repositories need the applicable GitHub Code Security plan and settings.
  • Findings must be reviewed before sharing them outside the repository owner’s organization.

Want priorities instead of a raw report? Open Request paid interpretation with only non-confidential context. A fixed-scope human review can turn the preflight into a one-problem diagnosis, AI Repo Enablement, modernization assessment or remediation plan.

Formats and contact: https://dotnet-audit-studio.dtauskanov3.chatgpt.site/en

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

Version Downloads Last Updated
1.0.1 117 8/13/2026
1.0.0 114 7/29/2026