Skip to content

Feedback requested: IgniteUI.Blazor.Lite 0.1.2-alpha.3 readiness assessment #402

Description

@PureWeen

Hello Infragistics team — we completed a bounded, evidence-based review of the public IgniteUI.Blazor.Lite 0.1.2-alpha.3 package at source commit 65e8af57a54edc3a098dd16dea7ce5d287a3c5d2 and would appreciate your corrections and context.

This is collaborative feedback, not certification, a security report, a release rejection, or an overall product rating. It covers 48 package-level requirements from a supplied Blazor partner-component requirements document; it does not assess every component or other Ignite UI editions.

Outcome overview

Result Count Meaning
Verified 14 Supported by the evidence obtained, subject to the stated qualifications.
Gap 6 A concrete conflict with a requirement was observed.
Maintainer evidence requested 12 Depends on records or decisions unavailable to the reviewer; these are not established defects.
Not tested 10 Available evidence or completed probes were insufficient; these are not established defects.
Not applicable 6 Does not apply to the bounded package surface.

What looked good

  • The package declares MIT licensing and maps to a public source repository and exact commit.
  • The .nupkg author signature was verified, with the timestamp-revocation limitation retained in the report.
  • The selected release publishes SPDX 2.2 and SPDX 3.0 SBOMs.
  • The public release workflow uses NuGet OIDC trusted publishing rather than a long-lived publishing key.
  • The repository publishes a private security contact and public support routes.

Gaps identified

These are unranked and each should be read with its qualification in the attached report.

  • PI-08 — Bundled upstream coverage in the SBOM: The 11 locked npm name/version pairs represented in the shipped source maps are listed, but the bundled and attributed unicode_hack.js upstream/version is not identified in either published SPDX document.
  • BEQ-21 — Analyzer-clean builds on supported TFMs: An unchanged Release build with SDK 10.0.203 for net8.0, net9.0, and net10.0 exited successfully but emitted 2,472 Blazor warnings: 819 BL0007 and 5 BL0005 per TFM. This used an authorized substituted package-source environment and is not claimed to reproduce the historical release build or establish a regression.
  • BEQ-24 — Experimental API marking: IgbChat is documented as preview and evolving, but its two source partials and the bounded 312-file library scan contained no [Experimental] marker. The finding is limited to that observed marking conflict, not a broader SemVer failure.
  • AI-01 — Contribution of promoted AI skills: Four consumer skill hubs are promoted in the release source but are not present in the retrieved dotnet/skills main tree. Open dotnet/skills#1111 is credited as narrower setup-skill progress, not delivery of those four hubs.
  • AI-02 — Evaluation coverage for promoted AI skills: The four promoted skill hubs have the expected descriptive structure but no corresponding evaluation definitions. The five stimuli in the separate setup-only dotnet/skills#1111 proposal do not evaluate those four hubs.
  • AI-05 — Proprietary dependency path in generated guidance: The grids guidance directs some GridLite scenarios to IgbGrid from the licensed IgniteUI.Blazor package, and image-design guidance directs advanced scenarios to the full or trial suite. This concerns the promoted guidance path, not every generated output or the Lite package itself.

Complete outcome index

  • Verified: LP-01, LP-02, LP-05, LP-06, LP-07, LP-08, LP-09, PI-03, PI-05, PI-06, SEC-04, SEC-06, SUP-02, SUP-07
  • Gaps: PI-08, BEQ-21, BEQ-24, AI-01, AI-02, AI-05
  • Maintainer evidence requested: LP-03, SEC-01, SEC-02, SEC-03, SEC-05, SEC-08, SEC-09, SUP-01, SUP-08, SUP-10, AI-04, AI-06
  • Not tested: LP-04, LP-10, PI-01, PI-02, PI-07, PI-09, SEC-07, SUP-03, SUP-06, AI-03
  • Not applicable: SCF-01, SCF-02, SCF-03, SCF-04, SCF-05, SCF-06

SUP-10 concerns Microsoft promotion discretion rather than evidence Infragistics owns; it remains listed for transparency.

Full report

A ZIP attached to this issue contains:

  • infragistics-readiness-report.md — all 48 requirements, observations, qualifications, and follow-ups.
  • infragistics-readiness-evidence.md — corresponding sanitized evidence summaries.

The attachment intentionally excludes raw logs, credentials, local paths, session identifiers, internal recovery records, and private evidence.

How to provide feedback

Please reply with the relevant requirement ID and any correction, missing context, public evidence link, or intentional product decision. Partial replies are welcome; there is no need to respond to every row. Evidence-backed corrections can be recorded explicitly while preserving the original assessment.

Please do not post credentials, customer data, internal logs, or sensitive vulnerability details here; use an appropriate private security or support channel for anything sensitive.

Important limitations

  • Structural validation checked report consistency, selected scope, status vocabulary, and evidence-reference resolution; it did not prove factual truth or certify the product.
  • BEQ-21 used an unchanged source build in an authorized substituted package-source environment, not a historical release-build reproduction or repository-default feed result.
  • Missing maintainer evidence and incomplete tests are separate from product gaps.
  • The assessment is limited to the exact package version and source commit identified above.

infragistics-readiness-report.zip

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions