Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>Pubspec Health — SwiftPM, AGP 9 & Discontinued PackagesNew to Visual Studio Code? Get it now.
Pubspec Health — SwiftPM, AGP 9 & Discontinued Packages

Pubspec Health — SwiftPM, AGP 9 & Discontinued Packages

devShakib

| (0) | Free
Flags discontinued and retracted Flutter/Dart packages in pubspec.yaml, and the plugins in your dependency tree that still need CocoaPods (its registry goes read-only on 2 Dec 2026) or block AGP 9's built-in Kotlin. Quick fixes, and hovers with pub points, likes and downloads.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Pubspec Health

Your pubspec.yaml knows which packages you asked for. It doesn't tell you which of them pub.dev has marked discontinued, whether the version you're locked to was retracted, or which plugins deep in your tree still need CocoaPods — whose registry goes read-only on 2 December 2026 — or still apply the Kotlin Gradle Plugin, which AGP 9's built-in Kotlin rejects.

Pubspec Health puts each of those on the dependency line you can change.

pubspec.yaml with findings

What it checks

discontinued

The author has discontinued the package on pub.dev. When they named a successor, the quick fix swaps it in at its latest version (connectivity → connectivity_plus).

retracted

The version in your pubspec.lock was retracted by its author — pub.dev keeps it downloadable, but the author no longer stands behind it. The quick fix runs flutter pub upgrade <package> (dart pub upgrade in a Dart-only package).

swiftpm

A plugin your app builds for iOS or macOS ships a podspec but no Package.swift in the version you're locked to. Flutter now uses Swift Package Manager by default and falls back to CocoaPods for plugins like this; the CocoaPods registry becomes read-only on 2 December 2026.

The check reads the locked version from your pub cache, not pub.dev's tag (which only describes the latest release), and follows the dependency tree: a federated plugin's iOS code lives in a package you never wrote down (url_launcher → url_launcher_ios), so the finding lands on the line you can change. When a newer release has a Swift package, it says which; when none does, the quick fix opens a pre-filled issue for the maintainers, which you read and submit yourself.

Web-only plugins that ship stub podspecs, Dart-only plugins, and apps without an ios/ or macos/ folder are left alone.

built-in-kotlin

A plugin your Android app builds still applies the Kotlin Gradle Plugin (kotlin-android / org.jetbrains.kotlin.android). Flutter keeps android.builtInKotlin=false for now, so this is information — until your android/gradle.properties says android.builtInKotlin=true, at which point it's an error, because the build fails.

outdated

A newer release is out. Shown as a faint hint, not a squiggle — being behind is normal; being discontinued isn't.

not-resolved

There's no pubspec.lock yet, so nothing locked can be checked. Run flutter pub get.

How it reads your project

  • Locked versions, not constraints. ^3.0.0 says what you'd accept; pubspec.lock says what you got, and that's what gets checked, read from your local pub cache.
  • Per platform. An app with only ios/ is never told about a plugin's macOS code, and a plugin with a Swift package for iOS but a podspec for macOS only matters to apps that build for macOS.
  • Pub workspaces. A member with resolution: workspace is checked against the root's pubspec.lock. Sibling members (ds_ui: any) are never looked up on pub.dev, where an unrelated package may share the name, and plugins that reach an app through them are still found.
  • Once per plugin. A plugin you list yourself is reported on its own line, not again on every other dependency that also pulls it in.
  • Overrides. An override pins a version on purpose, so it's never called outdated, and a package that's also a regular dependency is reported there.

Also

  • Hover a dependency for its locked and latest versions, pub points, likes and 30-day downloads.
  • Status bar: a count of what needs attention across the workspace; click it for the list.
  • Run full health check (fhc) — runs the free flutter_health_check CLI over the project: Google Play and App Store rules (targetSdk, restricted permissions, purpose strings), leaked secrets, Firebase rules, vulnerable packages, analyzer results, tests and CI, written to health-report.html.

Settings

Setting Default
pubspecHealth.enable true Turn the checks off.
pubspecHealth.disabledChecks [] Any of discontinued, retracted, outdated, swiftpm, built-in-kotlin.
pubspecHealth.cacheHours 12 How long pub.dev answers are reused. pub.dev rate-limits bursts.

Privacy

It reads pubspec.yaml, pubspec.lock and your local pub cache, and asks pub.dev about the packages you depend on. Nothing else leaves your machine.

Development

node --test test/          # no dependencies to install
node tool/try.js ../app    # run the analyzer on a real project
npx --yes @vscode/vsce package --no-dependencies

MIT © K M Shahriar Hossain

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft