dotnet tool¶
- ID
dotnet- Links
- Upstream stars
⭐ 3,218
- Last commit
2026-09-29
- Version requirement
>= 8.0.400
- Platforms
🐧 Linux · 🍎 macOS · 🪟 Windows
- Operations
installed·search·install·upgrade·upgrade_all·remove- purl types
pkg:dotnet/·pkg:nuget/- CLI name
dotnet- Every call
dotnet tool <command>- Forced environment
DOTNET_CLI_TELEMETRY_OPTOUT=1DOTNET_CLI_UI_LANGUAGE=en-usDOTNET_NOLOGO=1- Issues and PRs
- Source
.NET global tools, the CLI programs the .NET SDK installs from NuGet.
Every operation goes through the dotnet tool subcommand group, forced by
DotNet.pre_args, and targets the user-wide scope with --global. Global
tools land under ~/.dotnet/tools and are never shared between users, so
no operation escalates: elevation is only ever needed for the separate
--tool-path scenario, which this wrapper does not drive.
What mpm adds to dotnet¶
Through mpm, dotnet gains --exact and --extended search, to narrow to exact names or match descriptions.
Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover dotnet alongside every other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your dotnet commands, in mpm¶
You already know dotnet: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
Search for a package |
|
|
Install a package |
|
|
Upgrade one package |
|
|
Upgrade everything |
|
|
Remove a package |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
Notes |
|---|---|---|
|
✅ |
|
|
❌ |
The SDK ships no way to compare installed tools against NuGet without mutating them (dotnet/sdk#22853, closed as not planned); |
|
||
|
✅ |
Exact and extended search backfilled by |
|
✅ |
|
|
✅ |
|
|
✅ |
|
|
✅ |
|
|
||
|
❌ |
Nothing clears only the global tools’ cache; |
|
Configuration¶
Ignore
dotneton thempmCLI by passing the--no-dotnetoption.Ignore it for every run in your configuration:
[mpm] dotnet = false
Raise the timeout of all
dotnetcalls:[mpm.overrides.dotnet] timeout = 900
Run
mpm config-template dotnetto print all overridable settings for your configuration file:[mpm.overrides.dotnet] cli_names = [ "dotnet", ] cli_search_path = [] dry_run = false ignore_auto_updates = true plan = false post_args = [] pre_args = [ "tool", ] pre_cmds = [] requirement = ">=8.0.400" stop_on_error = false unmaintained = false version_cli_options = [ "--version", ] version_regexes = [ "^(?P<version>\\d+\\.\\d+\\.\\d+\\S*)", ] [mpm.overrides.dotnet.extra_env] DOTNET_CLI_UI_LANGUAGE = "en-us" DOTNET_NOLOGO = "1" DOTNET_CLI_TELEMETRY_OPTOUT = "1"
The arguments and environment variables listed in the box atop this page are forced on every dotnet call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.
Recipes¶
A few jobs you would otherwise script around dotnet, one mpm command each:
Snapshot and clone a machine:
mpm --dotnet dump dotnet.toml, thenmpm restore dotnet.tomlon the next one.Export a compliance SBOM:
mpm --dotnet sbom(CycloneDX by default,--spdxfor SPDX).
Privilege escalation¶
mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.
None of its operations is privileged.
See privilege escalation for the full policy.
Cooldown¶
State of dotnet tool’s release-age gating, from the cooldown support table:
Status: 🚧 Proposed (scoped to
dotnet packageflows, notdotnet tool)Mechanism:
minPublishAgeHoursper source innuget.config(open spec)Reference: NuGet/Home#14657
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: NuGet.org (
pkg:nuget)Retraction: Yank (unlist): “nuget.org does not support permanent deletion of packages”, so an unlisted version leaves search and the gallery but “can still be downloaded and installed by using an exact version number” (policy). Malware is the carve-out, deleted outright, each removal landing in the public catalog as a
PackageDeleteleaf (catalog)Publish date: ✅
publishedon each registrationcatalogEntry, but overwritten with1900-01-01T00:00:00+00:00the moment a version is unlisted, and absent from the search resource (API)
With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.
Reference traces¶
A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know dotnet tool well and a transcript below looks wrong, or a newer release changed its output format, report it.
$ dotnet tool list --global
Package Id Version Commands
--------------------------------------
dotnet-ef 2.1.11 dotnet-ef
Version check¶
The version is probed by running:
$ dotnet --version
9.0.306
and extracted with:
r"^(?P<version>\d+\.\d+\.\d+\S*)"
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
8.0.0(2026-09-20)Resolve the
pkg:conda,pkg:golang,pkg:haxeandpkg:nugetpURL types to these managers, which raised instead of routing.Add the .NET global tool manager with
installed,search,install,upgradeandremovesupport, including version pinning, its localized listings pinned to one language.