Libman.Audit 1.0.0

dotnet add package Libman.Audit --version 1.0.0
                    
NuGet\Install-Package Libman.Audit -Version 1.0.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Libman.Audit" Version="1.0.0">
  <PrivateAssets>all</PrivateAssets>
  <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets>
</PackageReference>
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Libman.Audit" Version="1.0.0" />
                    
Directory.Packages.props
<PackageReference Include="Libman.Audit">
  <PrivateAssets>all</PrivateAssets>
  <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets>
</PackageReference>
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Libman.Audit --version 1.0.0
                    
#r "nuget: Libman.Audit, 1.0.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Libman.Audit@1.0.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Libman.Audit&version=1.0.0
                    
Install as a Cake Addin
#tool nuget:?package=Libman.Audit&version=1.0.0
                    
Install as a Cake Tool

Libman.Audit

.NET CI/CD

A security audit tool for LibMan (Library Manager) that automatically scans your libman.json file for known security vulnerabilities in client-side libraries during the build process.

Features

  • 🔍 Automatic vulnerability scanning during MSBuild
  • 🚨 GitHub Advisory Database integration for up-to-date vulnerability information
  • 🎯 Supports multiple LibMan providers (cdnjs, unpkg, jsdelivr)
  • 🛑 Build failures for Critical and High severity vulnerabilities
  • ⚠️ Build warnings for Medium and Low severity vulnerabilities
  • 📊 Detailed vulnerability reporting with severity levels and counts
  • 🔧 Zero configuration - works automatically when installed
  • 🎨 Multi-targeting - supports MSBuild for .NET Framework and .NET (8+)

Installation

Install the NuGet package in your ASP.NET Core or web project:

Package Manager Console

dotnet add package Libman.Audit

PackageReference

<PackageReference Include="Libman.Audit" Version="..." />

How It Works

Libman.Audit automatically integrates with your build process and:

  1. Scans your libman.json file for client-side library dependencies
  2. Queries the GitHub Advisory Database for known vulnerabilities
  3. Reports findings during build with appropriate severity levels
  4. Fails the build for Critical/High severity vulnerabilities
  5. Shows warnings for Medium/Low severity vulnerabilities

Usage

Automatic Integration

Once installed, Libman.Audit runs automatically during every build. No configuration required!

Supported Providers

Libman.Audit supports the LibMan providers that source from well-known packages:

  • cdnjs
  • unpkg
  • jsdelivr

Note: filesystem provider is not supported as it does not catalog well-known libraries.

Default Vulnerability Severity Levels

Severity Build Action Description
Critical ❌ Build Error Immediate action required
High ❌ Build Error Should be addressed promptly
Medium ⚠️ Build Warning Should be reviewed and planned for remediation
Low ⚠️ Build Warning Consider updating when convenient
Unknown ⚠️ Build Warning Severity could not be determined

Configuration

Disable for Specific Projects

To disable Libman.Audit for a specific project, add this to your .csproj file:

<PropertyGroup>
  <SkipLibmanAudit>true</SkipLibmanAudit>
</PropertyGroup>
There are no supported framework assets in this package.

Learn more about Target Frameworks and .NET Standard.

  • .NETFramework 4.8

    • No dependencies.
  • net8.0

    • No dependencies.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.0 4,619 8/16/2025