Skip to content

[WIP] Fix dependency resolver for detecting downgrades - #14775

Closed
jeffkl with Copilot wants to merge 1 commit into
devfrom
copilot/fix-dependency-resolver-downgrade
Closed

jeffkl with Copilot wants to merge 1 commit into
devfrom
copilot/fix-dependency-resolver-downgrade

Conversation

Copilot AI commented Feb 26, 2026

Copy link
Copy Markdown
Contributor

Thanks for assigning this issue to me. I'm starting to work on it and will keep this PR's description up to date as I form a plan and make progress.

Original prompt

This section details on the original issue you should resolve

<issue_title>New dependency resolver can miss detecting downgrade</issue_title>
<issue_description>### NuGet Product Used

MSBuild.exe

Product Version

all

Worked before?

No response

Impact

None

Repro Steps & Context

Create the following project files:

ClassLibrary1.csproj

<Project Sdk="Microsoft.NET.Sdk">
  <PropertyGroup>
    <TargetFramework>net8.0</TargetFramework>
  </PropertyGroup>
  <ItemGroup>
    <PackageReference Include="Azure.Core" />
    <PackageReference Include="System.ClientModel" />
  </ItemGroup>
</Project>

Directory.Packages.props

<Project>
  <PropertyGroup>
    <ManagePackageVersionsCentrally>true</ManagePackageVersionsCentrally>
    <CentralPackageTransitivePinningEnabled>true</CentralPackageTransitivePinningEnabled>
  </PropertyGroup>
  <ItemGroup>
    <PackageVersion Include="Azure.Core" Version="1.50.0" />
    <PackageVersion Include="System.ClientModel" Version="1.0.0" />
  </ItemGroup>
</Project>

To workaround the problem, users have to enable to legacy dependency resolver:

<PropertyGroup>
  <RestoreUseLegacyDependencyResolver>true</RestoreUseLegacyDependencyResolver>
</PropertyGroup>

Verbose Logs

The following error should be logged:


Detected package downgrade: System.ClientModel from 1.8.0 to 1.0.0. Reference the package directly from the project to select a different version.
  ClassLibrary1 -> Azure.Core 1.50.0 -> System.ClientModel (>= 1.8.0)
  ClassLibrary1 -> System.ClientModel (>= 1.0.0)
```</issue_description>

<agent_instructions>A direct dependency isn't a transitively pinned one. So this should be a downgrade with the appropriate error.</agent_instructions>

## Comments on the Issue (you are @copilot in this section)

<comments>
</comments>

💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.

@jeffkl

jeffkl commented Feb 26, 2026

Copy link
Copy Markdown
Contributor

@copilot code review[agent] try again

@jeffkl jeffkl closed this Feb 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

New dependency resolver can miss detecting downgrade

2 participants