NuGet upgrade planner

Paste a packages.config or a project file. Each package is looked up on nuget.org, from your browser, and the result lists what stands between the project and the .NET you are aiming at: published vulnerabilities, deprecated packages, packages with no release for the target, and how far behind each one is. Download it as a report to attach to the upgrade ticket.

Package names and versions go to api.nuget.org from your browser, as they would from Visual Studio. Nothing is sent to us unless you choose to send the result at the end.

How to read the result

Installed and latest
The version in your file against the newest stable, listed release on nuget.org. Pre-releases and unlisted versions are ignored.
Supports the target
Whether any release of the package declares support for the .NET you chose, read from the frameworks its dependencies are declared for. "Not stated" means the package declares no dependencies, so the metadata is silent; check its page.
What to do
One line per package, in order of urgency: published vulnerabilities and deprecations first, then packages with no release for the target, then major version steps, then routine updates.

What it reads

For each package, the nuget.org registration record: every version with its publish date, whether it is listed, the deprecation notice if the authors have added one, the security advisories nuget.org attaches to a version (from the GitHub Advisory Database), the licence, and the frameworks each version declares its dependencies for.

From those it works out the latest stable release, how far behind the installed version is, whether the installed version has a published advisory that a newer release fixes, and whether any release supports the target: .NET Standard 2.0 and 2.1, .NET Core, and .NET 5 to the target version count for .NET 8 and 10; .NET Framework 2.0 to 4.8 and .NET Standard up to 2.0 count for .NET Framework 4.8. A release that targets only net8.0-windows is marked Windows only.

What it cannot tell you

Frameworks a package does not declare
Support is read from the dependency groups in the package metadata. A package that ships assemblies for .NET 8 but declares no dependencies shows as "not stated", not as supported.
Packages that other packages pull in
packages.config lists them; a PackageReference project does not. Dependencies of dependencies are not expanded here.
Private feeds
Only nuget.org is consulted. Packages from an internal feed show as not found.
How your code uses a package
A major version step may or may not break your code. The planner says that a step exists; the compiler says what it costs.

Next steps

If the file was a packages.config, the project will need to move to PackageReference before it can target modern .NET: our converter writes the ItemGroup and lists what to remove from the project file. The web.config has its own conversion: web.config to appsettings.json.

Packages with no release for the target are where upgrades stall. Our .NET upgrade assessment goes through exactly these, with the code, and sets out the route and the cost before anything is changed.

A package list full of red?

Send it to us. We will say which items block the move, which are routine, and what the upgrade is likely to involve.

Tell us about your system 0800 433 7990 Monday to Friday, 9am to 5pm. A first 20-minute call is free, and we reply to every enquiry within one working day. What happens after you get in touch