/outdated
What
A three-layer dependency health report:
- Inventory — every
PackageReferenceper project, with TFMs and central package management awareness, via theget_nuget_packagesMCP tool (no network, token-cheap). - Staleness + vulnerabilities — current vs latest stable, and known CVEs,
via the
dotnetCLI. - License screen — flags packages that moved to commercial licenses so an
innocent
dotnet outdated --upgradedoesn't silently change your legal position.
The output is a single prioritized table — vulnerabilities first, license traps second, staleness last — with a recommended action per row.
When
- "check for outdated packages", "package audit", "dependency health"
- Before a .NET version upgrade (pairs with
/migrateFlow B) - After inheriting an unfamiliar codebase
- Dependabot/NuGet audit warnings appeared and you want the full picture
- Periodically on long-lived projects — quarterly is a good cadence
How
Step 1: Inventory (MCP, no network)
Returns per-project {Name, TargetFramework, Cpm, Packages: [{Id, Version}]}.
Note Cpm: true — updates then belong in Directory.Packages.props, not the
csproj. Flag mixed TFMs across projects while you're here.
Step 2: Staleness and vulnerabilities (CLI)
Both need a successful restore first. If restore fails, fix that before auditing — a broken lock state makes version output unreliable.
Step 3: License screen
Check the inventory against the known commercial moves (full rationale in
knowledge/package-recommendations.md):
A license flag fires when the project is on the free major and a naive "update all" would cross the boundary — that is the trap this step exists for.
Step 4: Report
One table, priority-ordered:
Step 5: Act (optional)
Offer to execute updates via /migrate Flow C — one package at a time,
dotnet build && dotnet test between each. Never batch major updates:
batched failures are unattributable.
MCP Tools Used
get_nuget_packages— inventory, CPM detection, TFM auditget_diagnostics— verify the solution still compiles clean after updates
Example
Related
/migrate— Flow C executes the updates this report recommendsknowledge/package-recommendations.md— vetted packages + licensing detailknowledge/mediatr-to-mediator-migration.md— step-by-step MediatR exit/verify— full pipeline after applying updates


