NuGet upgrade planner
Paste a packages.config or a project file. Each package is looked up on nuget.org, from your browser, and the result lists what stands between the project and the .NET you are aiming at: published vulnerabilities, deprecated packages, packages with no release for the target, and how far behind each one is. Download it as a report to attach to the upgrade ticket.
Result
| Package | Installed | Latest | Supports .NET 8 | What to do |
|---|
How to read the result
- Installed and latest
- The version in your file against the newest stable, listed release on nuget.org. Pre-releases and unlisted versions are ignored.
- Supports the target
- Whether any release of the package declares support for the .NET you chose, read from the frameworks its dependencies are declared for. "Not stated" means the package declares no dependencies, so the metadata is silent; check its page.
- What to do
- One line per package, in order of urgency: published vulnerabilities and deprecations first, then packages with no release for the target, then major version steps, then routine updates.
What it reads
For each package, the nuget.org registration record: every version with its publish date, whether it is listed, the deprecation notice if the authors have added one, the security advisories nuget.org attaches to a version (from the GitHub Advisory Database), the licence, and the frameworks each version declares its dependencies for.
From those it works out the latest stable release, how far behind the installed version is, whether the installed version has a published advisory that a newer release fixes, and whether any release supports the target: .NET Standard 2.0 and 2.1, .NET Core, and .NET 5 to the target version count for .NET 8 and 10; .NET Framework 2.0 to 4.8 and .NET Standard up to 2.0 count for .NET Framework 4.8. A release that targets only net8.0-windows is marked Windows only.
What it cannot tell you
- Frameworks a package does not declare
- Support is read from the dependency groups in the package metadata. A package that ships assemblies for .NET 8 but declares no dependencies shows as "not stated", not as supported.
- Packages that other packages pull in
- packages.config lists them; a PackageReference project does not. Dependencies of dependencies are not expanded here.
- Private feeds
- Only nuget.org is consulted. Packages from an internal feed show as not found.
- How your code uses a package
- A major version step may or may not break your code. The planner says that a step exists; the compiler says what it costs.
Next steps
If the file was a packages.config, the project will need to move to PackageReference before it can target modern .NET: our converter writes the ItemGroup and lists what to remove from the project file. The web.config has its own conversion: web.config to appsettings.json.
Packages with no release for the target are where upgrades stall. Our .NET upgrade assessment goes through exactly these, with the code, and sets out the route and the cost before anything is changed.
A package list full of red?
Send it to us. We will say which items block the move, which are routine, and what the upgrade is likely to involve.