CLI tool
dotnet/runtime avatar
dotnet/runtime

dotnet/runtime: The Source Repository for the .NET Cross-Platform Runtime

.NET is a cross-platform runtime for cloud, mobile, desktop, and IoT apps.

18,313 stars5,631 forksC#MIT

At a glance

What is it?
The dotnet/runtime repository contains the source code for the .NET runtime, base class libraries, and the shared host installer for all supported platforms. It targets contributors, platform porters, and engineers who need to understand or modify the runtime itself, not developers building applications on top of .NET.
Who is it for?
The dotnet/runtime repository is the right starting point for engineers contributing to .NET itself, porting .NET to a new platform, investigating a runtime bug, or studying how the base class libraries are implemented. Application developers who need to use .NET should install official releases from dotnet.microsoft.com rather than building from this repository.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
Mainly C#, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What This Repository Contains and Who It Is For

The dotnet/runtime repository holds the code to build the .NET runtime, libraries, and shared host (`dotnet`) installers for all supported platforms, as well as the runtime and library source themselves. The README describes .NET as a cross-platform runtime for cloud, mobile, desktop, and IoT applications.

This repository is for engineers who work on the runtime itself: contributors fixing bugs or adding features, porters bringing .NET to new operating systems or CPU architectures, and developers investigating issues that trace to the runtime or base class libraries. It is not the source for application frameworks like ASP.NET Core or Entity Framework Core, which live in separate repositories. The README links to a .NET home repository at github.com/Microsoft/dotnet that aggregates links to hundreds of .NET-related projects.

Repository Structure and Key Directories

The repository root contains a `src/` directory that holds the bulk of the source code, divided between the runtime (CoreCLR, NativeAOT, Mono) and the libraries (the base class library and platform-specific implementations). The `eng/` directory contains build engineering scripts and CI configuration. The `docs/` directory holds contributor documentation, with workflow instructions in `docs/workflow/README.md`.

The top-level build entry points are `build.cmd` for Windows and `build.sh` for Linux and macOS. These scripts configure the build using the MSBuild project `Build.proj`. The `global.json` at the root pins the .NET SDK version used to build the repository itself, and `NuGet.config` configures package source feeds.

Additional tooling files at the root include `.clang-format` and `.clang-tidy` for C/C++ code quality, a `.devcontainer/` configuration for container-based development, and a `THIRD-PARTY-NOTICES.TXT` listing third-party licenses. A `.claude/` directory is also present in the top-level tree, indicating AI agent configuration has been added to the repository.

Building and Testing the Runtime

The README points to `docs/workflow/README.md` for build and test instructions. The general pattern involves running the platform-appropriate build script from the repository root. The `dotnet.cmd` and `dotnet.sh` scripts at the root are bootstrappers that acquire the correct .NET SDK version for building.

The README also mentions dogfooding nightly builds: `docs/project/dogfooding.md` explains how to configure a project to use nightly builds of the runtime and libraries to test them before release. This is the recommended approach for testing a potential fix in a real application before the fix lands in an official release.

Contributions go through a pull request process on GitHub. The `CONTRIBUTING.md` file describes what kinds of contributions are accepted, and the build and test workflow. Issues should be filed in this repository only when they are tied to the runtime, the class libraries, or the installation of the `dotnet` binary. Issues for other .NET components (ASP.NET Core, for example) belong in their respective repositories, and the README links to a new-issue page that routes to the correct repository.

Release Cadence and Active Branches

The repository maintains multiple active release branches simultaneously. The most recent GitHub releases are .NET 10.0.12, .NET 9.0.20, and .NET 8.0.31, all released on 2026-09-08. The support policy for each release version is documented at github.com/dotnet/core/blob/main/support.md.

.NET follows an annual release cadence, with even-numbered versions designated as Long-Term Support (LTS) releases and odd-numbered versions as Standard-Term Support (STS). .NET 8 is an LTS release; .NET 9 is STS; .NET 10 will be LTS. The LTS and STS distinction determines how long a release receives security patches and bug fixes. The roadmap is at github.com/dotnet/core/blob/main/roadmap.md.

The last push to the repository was on 2026-09-26, confirming active development across multiple concurrent release branches.

Security Reporting and the Bounty Program

The README specifies a private disclosure path for security issues: report to the Microsoft Security Response Center (MSRC) via the MSRC Researcher Portal at msrc.microsoft.com/report/vulnerability/new. The project promises a response within 24 hours. This path is separate from GitHub Issues, which are public and should not be used for security vulnerabilities.

Microsoft also runs a .NET Bounty Program for qualifying vulnerabilities, referenced in the README. The `SECURITY.md` file in the repository contains the full security reporting instructions. Any public GitHub issue that contains a security vulnerability description will be taken down and the reporter redirected to the private disclosure path.

License and Governance

The .NET runtime is licensed under the MIT license. The `LICENSE.TXT` and `PATENTS.TXT` files at the repository root cover the runtime source. Third-party component licenses are listed in `THIRD-PARTY-NOTICES.TXT`.

The project is governed as a .NET Foundation project. The README links to the .NET Foundation home at dotnetfoundation.org. The community has adopted the Contributor Covenant code of conduct, documented in `CODE-OF-CONDUCT.md` and the .NET Foundation Code of Conduct at dotnetfoundation.org/code-of-conduct.

For general OSS discussions about the .NET ecosystem, the README points to .NET Foundation Discussions rather than this repository's issue tracker. The .NET Discord server at aka.ms/dotnet-discord is the recommended place for real-time conversation about .NET development.

When to Use This Repository Versus Installing .NET

Application developers should not build .NET from this repository. Installing from dotnet.microsoft.com or through a system package manager is the correct path for application development. Building from source is time-consuming, requires specific toolchain versions, and produces a runtime that may not match the official binaries in subtle ways.

The right use cases for this repository are: investigating a reported runtime bug and tracing it to source, building a custom .NET runtime for an unsupported platform, contributing a fix or feature back to .NET, or studying the implementation of a specific base class library type. The `docs/workflow/README.md` file covers how to run specific test suites after a source change, and `docs/project/dogfooding.md` explains how to substitute a custom-built runtime into a real application for integration testing.

Mono, OpenJDK's HotSpot JVM, and GraalVM are alternative managed runtime implementations for comparison. Mono was historically the open-source .NET implementation before Microsoft open-sourced .NET Core; its source is now included within this repository under `src/mono`. The unified repository approach means the Mono and CoreCLR runtimes share the same base class library implementation.

Editorial conclusion

The dotnet/runtime repository is the right starting point for engineers contributing to .NET itself, porting .NET to a new platform, investigating a runtime bug, or studying how the base class libraries are implemented. Application developers who need to use .NET should install official releases from dotnet.microsoft.com rather than building from this repository. Security issues should go to the Microsoft Security Response Center through the private disclosure path in SECURITY.md, not as public GitHub issues. The current active release branches are .NET 10.0.12, .NET 9.0.20, and .NET 8.0.31, all released on 2026-09-08.

Frequently asked questions

What is the .NET runtime?

The .NET runtime is the execution engine for .NET applications: it compiles and runs managed code, handles memory through garbage collection, and provides the base class libraries. This repository contains the source code for CoreCLR, NativeAOT, and Mono, which are the three runtime implementations shipped with .NET.

How do I contribute to dotnet/runtime?

Read `CONTRIBUTING.md` for accepted contribution types and the coding style guide, then follow `docs/workflow/README.md` for build and test instructions. File issues only for bugs tied to the runtime, base class libraries, or the dotnet host installer; other .NET components have their own repositories.

Which .NET versions are actively maintained in this repository?

The repository currently ships .NET 10.0.12, .NET 9.0.20, and .NET 8.0.31. Each version is maintained on its own branch. The support lifetime for each release is documented at github.com/dotnet/core/blob/main/support.md.

Official sources

  1. Official documentation
  2. Official README
  3. Project repository
  4. Release notes
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/dotnet-runtime.svg)](https://hysenlabs.com/projects/dotnet-runtime)