Libman.Audit
1.0.0
dotnet add package Libman.Audit --version 1.0.0
NuGet\Install-Package Libman.Audit -Version 1.0.0
<PackageReference Include="Libman.Audit" Version="1.0.0"> <PrivateAssets>all</PrivateAssets> <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets> </PackageReference>
<PackageVersion Include="Libman.Audit" Version="1.0.0" />
<PackageReference Include="Libman.Audit"> <PrivateAssets>all</PrivateAssets> <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets> </PackageReference>
paket add Libman.Audit --version 1.0.0
#r "nuget: Libman.Audit, 1.0.0"
#:package Libman.Audit@1.0.0
#addin nuget:?package=Libman.Audit&version=1.0.0
#tool nuget:?package=Libman.Audit&version=1.0.0
Libman.Audit
A security audit tool for LibMan (Library Manager) that automatically scans your libman.json file for known security vulnerabilities in client-side libraries during the build process.
Features
- 🔍 Automatic vulnerability scanning during MSBuild
- 🚨 GitHub Advisory Database integration for up-to-date vulnerability information
- 🎯 Supports multiple LibMan providers (cdnjs, unpkg, jsdelivr)
- 🛑 Build failures for Critical and High severity vulnerabilities
- ⚠️ Build warnings for Medium and Low severity vulnerabilities
- 📊 Detailed vulnerability reporting with severity levels and counts
- 🔧 Zero configuration - works automatically when installed
- 🎨 Multi-targeting - supports MSBuild for .NET Framework and .NET (8+)
Installation
Install the NuGet package in your ASP.NET Core or web project:
Package Manager Console
dotnet add package Libman.Audit
PackageReference
<PackageReference Include="Libman.Audit" Version="..." />
How It Works
Libman.Audit automatically integrates with your build process and:
- Scans your
libman.jsonfile for client-side library dependencies - Queries the GitHub Advisory Database for known vulnerabilities
- Reports findings during build with appropriate severity levels
- Fails the build for Critical/High severity vulnerabilities
- Shows warnings for Medium/Low severity vulnerabilities
Usage
Automatic Integration
Once installed, Libman.Audit runs automatically during every build. No configuration required!
Supported Providers
Libman.Audit supports the LibMan providers that source from well-known packages:
- cdnjs
- unpkg
- jsdelivr
Note: filesystem provider is not supported as it does not catalog well-known libraries.
Default Vulnerability Severity Levels
| Severity | Build Action | Description |
|---|---|---|
| Critical | ❌ Build Error | Immediate action required |
| High | ❌ Build Error | Should be addressed promptly |
| Medium | ⚠️ Build Warning | Should be reviewed and planned for remediation |
| Low | ⚠️ Build Warning | Consider updating when convenient |
| Unknown | ⚠️ Build Warning | Severity could not be determined |
Configuration
Disable for Specific Projects
To disable Libman.Audit for a specific project, add this to your .csproj file:
<PropertyGroup>
<SkipLibmanAudit>true</SkipLibmanAudit>
</PropertyGroup>
Learn more about Target Frameworks and .NET Standard.
-
.NETFramework 4.8
- No dependencies.
-
net8.0
- No dependencies.
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.0.0 | 4,619 | 8/16/2025 |