dotnet restore仍拉取漏洞版本,如何强制使用指定高版本?
解决NuGet依赖冲突:强制System.Text.Json使用指定高版本
问题场景
执行dotnet restore时报错:无法拉取System.Text.Json.7.0.3包——该版本存在漏洞,内部NuGet服务器已下架。已在.csproj中手动引入9.0.3版本的引用,但restore仍尝试拉取旧版本。
当前项目的.csproj片段:
<PropertyGroup> <TargetFramework>net8.0</TargetFramework> </PropertyGroup> <ItemGroup> <ProjectReference Include="..\Common\Common.csproj" /> <ProjectReference Include="..\Core\Core.csproj" /> <ProjectReference Include="..\Model\Model.csproj" /> </ItemGroup> <ItemGroup> <PackageReference Include="AutoMapper" Version="13.0.1" /> <PackageReference Include="EntityCloner.Microsoft.EntityFrameworkCore" Version="8.0.0" /> <PackageReference Include="log4net" Version="2.0.14" /> <PackageReference Include="Microsoft.CSharp" Version="4.7.0" /> <PackageReference Include="Microsoft.EntityFrameworkCore.SqlServer" Version="9.0.1" /> <PackageReference Include="SonarAnalyzer.CSharp" Version="8.0.0.9566" /> <PackageReference Include="System.ComponentModel.Annotations" Version="5.0.0" /> <PackageReference Include="System.Data.DataSetExtensions" Version="4.5.0" /> <PackageReference Include="system.private.uri" Version="4.3.2" /> <PackageReference Include="system.text.json" Version="9.0.3" /> <PackageReference Include="System.IO.Packaging" Version="9.0.2" /> <PackageReference Include="System.Security.Cryptography.Pkcs" Version="9.0.2" /> <PackageReference Include="Microsoft.Extensions.Caching.Memory" Version="9.0.2" /> </ItemGroup> </Project>
第一步:定位引用旧版本的依赖
先找出哪个包在请求7.0.3版本,执行以下命令:
- 快速筛选依赖树(Windows/Linux/macOS区分命令):
# Windows系统 dotnet list package --include-transitive | findstr /i "System.Text.Json" # Linux/macOS系统 dotnet list package --include-transitive | grep -i "System.Text.Json" - 查看详细restore日志,获取完整依赖链:
注意:还要检查引用的# Windows系统 dotnet restore --verbosity detailed | findstr /i "System.Text.Json" # Linux/macOS系统 dotnet restore --verbosity detailed | grep -i "System.Text.Json"Common.csproj、Core.csproj、Model.csproj这三个项目,它们可能自身依赖了旧版本的System.Text.Json。
第二步:强制全局使用高版本
1. 在.csproj中锁死版本
修改PackageReference配置,强制覆盖所有间接依赖:
<ItemGroup> <PackageReference Include="System.Text.Json" Version="9.0.3"> <PrivateAssets>all</PrivateAssets> <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets> </PackageReference> </ItemGroup>
或者在项目的<PropertyGroup>中添加全局版本变量,统一所有依赖的版本:
<PropertyGroup> <TargetFramework>net8.0</TargetFramework> <!-- 全局指定System.Text.Json版本 --> <SystemTextJsonVersion>9.0.3</SystemTextJsonVersion> </PropertyGroup>
2. 用NuGet.config做绑定重定向
在项目根目录的NuGet.config中添加以下配置,将所有旧版本请求重定向到9.0.3:
<configuration> <runtime> <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1"> <dependentAssembly> <assemblyIdentity name="System.Text.Json" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" /> <bindingRedirect oldVersion="0.0.0.0-9.0.3.0" newVersion="9.0.3.0" /> </dependentAssembly> </assemblyBinding> </runtime> </configuration>
3. 清理本地NuGet缓存
本地缓存残留的旧包可能导致restore异常,先清理再重试:
dotnet nuget locals all --clear
之后重新执行dotnet restore。
4. 同步更新引用项目的依赖
确保Common、Core、Model三个项目也将System.Text.Json升级到9.0.3版本,避免它们的依赖拉低版本。
内容的提问来源于stack exchange,提问作者Viktor Stjärne
相关产品推荐
相关产品推荐

