dotnet / dotnet/aspnetcore

Add validation to test that OOB packages have no SharedFx-only references

Open
#50,402 3 comments 0 reactions 1 assignee Claimed by @wtgodbe View on GitHub
area-infrastructure
Dominant language
C#
Stars
38.4k
Forks
10.9k
Avg merge
2d 6h
Merged PRs (30d)
290

Description

We had a situation in 8.0 where `Microsoft.Extensions.Caching.StackExchangeRedis` (which is an OOB package) added a dependency on `Microsoft.AspNetCore.OutputCaching` (which is SharedFx-only), which caused `StackExchangeRedis` to have a FrameworkReference on AspNetCore.App. This means devs using `StackExchangeRedis` would need to have Asp.Net installed on their machine in order to use the package, which goes against the principle of an OOB package (they should be useable by non-asp.net devs). We should add validation, maybe in `ResolveReferences.targets`, that prevents this from happening again, as it's a very easy mistake to make.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.