Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens.
NuGet Package Manager
Inspect and update NuGet package families using ManagedCode NuGetPackageManager, the nuget-manager CLI, or its VS Code extension. USE FOR: checking outdated packages; dry-run family reviews; applying reviewed literal package and explicit project SDK version updates. DO NOT USE FOR: adding/removing packages; dependency graph resolution; authenticated private-feed setup. INVOKES: inspect declarations, preview and review exact versions, apply authorized changes, then restore and run focused regressions.
Trigger On
- Checking outdated NuGet declarations with
nuget-manager. - Reviewing or applying one package family, such as
Microsoft.Orleans, across projects and Central Package Management files. - Using the ManagedCode NuGet Package Manager extension in VS Code.
Workflow
- Install the public tool and confirm its current help.
- Select a workspace, family, policy and prerelease scope; check feeds and preview exact edits.
- Review the owning files and target versions, apply the authorized selection, then restore, build and run focused regressions.
Install
dotnet tool install --global nuget-manager
nuget-manager --help
For an existing installation, use dotnet tool update --global nuget-manager. This is a global tool, not an application PackageReference. The upstream repository publishes both the tool and a VS Code extension. Install the extension from the Marketplace or a released VSIX.
Inspect and Review
Run a read-only family check, then preview exact proposed edits:
nuget-manager check --path . --family Microsoft.Orleans --policy minor --json
nuget-manager update --path . --family Microsoft.Orleans --policy minor --dry-run --json
Microsoft.Orleans selects the exact ID and dot-boundary descendants, never Microsoft.OrleansExtra. Each package keeps its own available target version; selecting a family does not force a shared version or establish compatibility. Inspect every target version and owning file, including central declarations consumed by multiple projects.
Apply and Validate
After reviewing the preview, apply the same selection:
nuget-manager update --path . --family Microsoft.Orleans --policy minor --yes
git diff -- '*.csproj' '*.fsproj' '*.vbproj' 'Directory.Packages.props'
dotnet restore
dotnet build --no-restore
dotnet test --no-build
Use --yes only when writing that selection is authorized. Without it, update uses the interactive review. Run the repository's focused regressions after restore/build; keep unrelated tests parallel and respect the repository's test-output budget. The tool does not restore or test automatically. If a file changed since the review snapshot, refresh and review again before applying.
flowchart LR
Check[Read declarations and listed feed versions] --> Preview[Dry-run exact family edits]
Preview --> Review[Review versions and owning files]
Review --> Apply[Validate snapshots and apply version edits]
Apply --> Verify[Restore, build, focused regressions]Deliver
Report the chosen family, policy and prerelease scope, reviewed files and versions, applied diff, and restore/build/regression results. Distinguish a failed feed check from a successful check with no updates.
Validate
- Confirm installed help matches the commands before automation.
- Confirm the dry-run leaves version files unchanged and the apply diff contains only reviewed literal versions.
- Confirm stale reviews are refreshed and unsupported declarations remain explicit.
- Confirm focused consumer regressions pass after restoring the changed versions.
Related skills
Convert .NET projects and solutions (.sln, .slnx) to NuGet Central Package Management (CPM) using Directory.Packages.props.
Building AI agents on .NET?
Managed Code builds production AI agents in C# and .NET.