Preserve NuGet lock graph identity - #4936
Merged
Merged
Conversation
Widthdom
marked this pull request as ready for review
July 27, 2026 16:21
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
packages.lock.jsonpackage and dependency node locations, including UTF-8/CRLF-aware lines, columns, spans, and package end ranges.changelog.d/unreleased/4845.fixed.md.Root cause
The lock-file extractor previously emitted approximate locations without a target qualifier or owning package for nested references. Candidate resolution then fell back to repository-wide name matches, which could bind identical package names across lock files and targets. Existing extraction and reference-identity contract markers also allowed stale persisted data to survive an update.
Validation
dotnet restore CodeIndex.sln-p:UseSharedCompilation=false: 0 warnings, 0 errorsorigin/mainsync: Issue Preserve package ownership, target scope, and source locations in packages.lock.json graphs #4845 tests passed on net8.0 and net9.0; dependency-lock tests passed 7/7 on each targetdotnet run --project tools/CodeIndex.Changelog -- check(18 fragments validated)status --check --jsonreports a fresh matching workspace with no failed checksAdversarial review
Completed the two required adversarial review rounds. Round 1 identified a cross-file npm lock candidate fallback. Round 2 identified dependency-lock file-level false edges plus missing extraction/reference contract invalidation. All findings were fixed and covered by targeted regression tests; no review finding remains unresolved.
Fixes #4845