Hello Infragistics team — we completed a bounded, evidence-based review of the public IgniteUI.Blazor.Lite 0.1.2-alpha.3 package at source commit 65e8af57a54edc3a098dd16dea7ce5d287a3c5d2 and would appreciate your corrections and context.
This is collaborative feedback, not certification, a security report, a release rejection, or an overall product rating. It covers 48 package-level requirements from a supplied Blazor partner-component requirements document; it does not assess every component or other Ignite UI editions.
Outcome overview
| Result |
Count |
Meaning |
| Verified |
14 |
Supported by the evidence obtained, subject to the stated qualifications. |
| Gap |
6 |
A concrete conflict with a requirement was observed. |
| Maintainer evidence requested |
12 |
Depends on records or decisions unavailable to the reviewer; these are not established defects. |
| Not tested |
10 |
Available evidence or completed probes were insufficient; these are not established defects. |
| Not applicable |
6 |
Does not apply to the bounded package surface. |
What looked good
- The package declares MIT licensing and maps to a public source repository and exact commit.
- The
.nupkg author signature was verified, with the timestamp-revocation limitation retained in the report.
- The selected release publishes SPDX 2.2 and SPDX 3.0 SBOMs.
- The public release workflow uses NuGet OIDC trusted publishing rather than a long-lived publishing key.
- The repository publishes a private security contact and public support routes.
Gaps identified
These are unranked and each should be read with its qualification in the attached report.
- PI-08 — Bundled upstream coverage in the SBOM: The 11 locked npm name/version pairs represented in the shipped source maps are listed, but the bundled and attributed
unicode_hack.js upstream/version is not identified in either published SPDX document.
- BEQ-21 — Analyzer-clean builds on supported TFMs: An unchanged Release build with SDK 10.0.203 for
net8.0, net9.0, and net10.0 exited successfully but emitted 2,472 Blazor warnings: 819 BL0007 and 5 BL0005 per TFM. This used an authorized substituted package-source environment and is not claimed to reproduce the historical release build or establish a regression.
- BEQ-24 — Experimental API marking:
IgbChat is documented as preview and evolving, but its two source partials and the bounded 312-file library scan contained no [Experimental] marker. The finding is limited to that observed marking conflict, not a broader SemVer failure.
- AI-01 — Contribution of promoted AI skills: Four consumer skill hubs are promoted in the release source but are not present in the retrieved
dotnet/skills main tree. Open dotnet/skills#1111 is credited as narrower setup-skill progress, not delivery of those four hubs.
- AI-02 — Evaluation coverage for promoted AI skills: The four promoted skill hubs have the expected descriptive structure but no corresponding evaluation definitions. The five stimuli in the separate setup-only
dotnet/skills#1111 proposal do not evaluate those four hubs.
- AI-05 — Proprietary dependency path in generated guidance: The grids guidance directs some GridLite scenarios to
IgbGrid from the licensed IgniteUI.Blazor package, and image-design guidance directs advanced scenarios to the full or trial suite. This concerns the promoted guidance path, not every generated output or the Lite package itself.
Complete outcome index
- Verified:
LP-01, LP-02, LP-05, LP-06, LP-07, LP-08, LP-09, PI-03, PI-05, PI-06, SEC-04, SEC-06, SUP-02, SUP-07
- Gaps:
PI-08, BEQ-21, BEQ-24, AI-01, AI-02, AI-05
- Maintainer evidence requested:
LP-03, SEC-01, SEC-02, SEC-03, SEC-05, SEC-08, SEC-09, SUP-01, SUP-08, SUP-10, AI-04, AI-06
- Not tested:
LP-04, LP-10, PI-01, PI-02, PI-07, PI-09, SEC-07, SUP-03, SUP-06, AI-03
- Not applicable:
SCF-01, SCF-02, SCF-03, SCF-04, SCF-05, SCF-06
SUP-10 concerns Microsoft promotion discretion rather than evidence Infragistics owns; it remains listed for transparency.
Full report
A ZIP attached to this issue contains:
infragistics-readiness-report.md — all 48 requirements, observations, qualifications, and follow-ups.
infragistics-readiness-evidence.md — corresponding sanitized evidence summaries.
The attachment intentionally excludes raw logs, credentials, local paths, session identifiers, internal recovery records, and private evidence.
How to provide feedback
Please reply with the relevant requirement ID and any correction, missing context, public evidence link, or intentional product decision. Partial replies are welcome; there is no need to respond to every row. Evidence-backed corrections can be recorded explicitly while preserving the original assessment.
Please do not post credentials, customer data, internal logs, or sensitive vulnerability details here; use an appropriate private security or support channel for anything sensitive.
Important limitations
- Structural validation checked report consistency, selected scope, status vocabulary, and evidence-reference resolution; it did not prove factual truth or certify the product.
BEQ-21 used an unchanged source build in an authorized substituted package-source environment, not a historical release-build reproduction or repository-default feed result.
- Missing maintainer evidence and incomplete tests are separate from product gaps.
- The assessment is limited to the exact package version and source commit identified above.
infragistics-readiness-report.zip
Hello Infragistics team — we completed a bounded, evidence-based review of the public
IgniteUI.Blazor.Lite0.1.2-alpha.3package at source commit65e8af57a54edc3a098dd16dea7ce5d287a3c5d2and would appreciate your corrections and context.This is collaborative feedback, not certification, a security report, a release rejection, or an overall product rating. It covers 48 package-level requirements from a supplied Blazor partner-component requirements document; it does not assess every component or other Ignite UI editions.
Outcome overview
What looked good
.nupkgauthor signature was verified, with the timestamp-revocation limitation retained in the report.Gaps identified
These are unranked and each should be read with its qualification in the attached report.
unicode_hack.jsupstream/version is not identified in either published SPDX document.net8.0,net9.0, andnet10.0exited successfully but emitted 2,472 Blazor warnings: 819BL0007and 5BL0005per TFM. This used an authorized substituted package-source environment and is not claimed to reproduce the historical release build or establish a regression.IgbChatis documented as preview and evolving, but its two source partials and the bounded 312-file library scan contained no[Experimental]marker. The finding is limited to that observed marking conflict, not a broader SemVer failure.dotnet/skillsmain tree. Opendotnet/skills#1111is credited as narrower setup-skill progress, not delivery of those four hubs.dotnet/skills#1111proposal do not evaluate those four hubs.IgbGridfrom the licensedIgniteUI.Blazorpackage, and image-design guidance directs advanced scenarios to the full or trial suite. This concerns the promoted guidance path, not every generated output or the Lite package itself.Complete outcome index
LP-01,LP-02,LP-05,LP-06,LP-07,LP-08,LP-09,PI-03,PI-05,PI-06,SEC-04,SEC-06,SUP-02,SUP-07PI-08,BEQ-21,BEQ-24,AI-01,AI-02,AI-05LP-03,SEC-01,SEC-02,SEC-03,SEC-05,SEC-08,SEC-09,SUP-01,SUP-08,SUP-10,AI-04,AI-06LP-04,LP-10,PI-01,PI-02,PI-07,PI-09,SEC-07,SUP-03,SUP-06,AI-03SCF-01,SCF-02,SCF-03,SCF-04,SCF-05,SCF-06SUP-10concerns Microsoft promotion discretion rather than evidence Infragistics owns; it remains listed for transparency.Full report
A ZIP attached to this issue contains:
infragistics-readiness-report.md— all 48 requirements, observations, qualifications, and follow-ups.infragistics-readiness-evidence.md— corresponding sanitized evidence summaries.The attachment intentionally excludes raw logs, credentials, local paths, session identifiers, internal recovery records, and private evidence.
How to provide feedback
Please reply with the relevant requirement ID and any correction, missing context, public evidence link, or intentional product decision. Partial replies are welcome; there is no need to respond to every row. Evidence-backed corrections can be recorded explicitly while preserving the original assessment.
Please do not post credentials, customer data, internal logs, or sensitive vulnerability details here; use an appropriate private security or support channel for anything sensitive.
Important limitations
BEQ-21used an unchanged source build in an authorized substituted package-source environment, not a historical release-build reproduction or repository-default feed result.infragistics-readiness-report.zip