You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

dotnet restore仍拉取漏洞版本,如何强制使用指定高版本?

解决NuGet依赖冲突:强制System.Text.Json使用指定高版本

问题场景

执行dotnet restore时报错:无法拉取System.Text.Json.7.0.3包——该版本存在漏洞,内部NuGet服务器已下架。已在.csproj中手动引入9.0.3版本的引用,但restore仍尝试拉取旧版本。

当前项目的.csproj片段:

<PropertyGroup>
  <TargetFramework>net8.0</TargetFramework>
</PropertyGroup>
<ItemGroup>
  <ProjectReference Include="..\Common\Common.csproj" />
  <ProjectReference Include="..\Core\Core.csproj" />
  <ProjectReference Include="..\Model\Model.csproj" />
</ItemGroup>
<ItemGroup>
  <PackageReference Include="AutoMapper" Version="13.0.1" />
  <PackageReference Include="EntityCloner.Microsoft.EntityFrameworkCore" Version="8.0.0" />
  <PackageReference Include="log4net" Version="2.0.14" />
  <PackageReference Include="Microsoft.CSharp" Version="4.7.0" />
  <PackageReference Include="Microsoft.EntityFrameworkCore.SqlServer" Version="9.0.1" />
  <PackageReference Include="SonarAnalyzer.CSharp" Version="8.0.0.9566" />
  <PackageReference Include="System.ComponentModel.Annotations" Version="5.0.0" />
  <PackageReference Include="System.Data.DataSetExtensions" Version="4.5.0" />
  <PackageReference Include="system.private.uri" Version="4.3.2" />
  <PackageReference Include="system.text.json" Version="9.0.3" />
  <PackageReference Include="System.IO.Packaging" Version="9.0.2" />
  <PackageReference Include="System.Security.Cryptography.Pkcs" Version="9.0.2" />
  <PackageReference Include="Microsoft.Extensions.Caching.Memory" Version="9.0.2" />
</ItemGroup>
</Project>

第一步:定位引用旧版本的依赖

先找出哪个包在请求7.0.3版本,执行以下命令:

  • 快速筛选依赖树(Windows/Linux/macOS区分命令):
    # Windows系统
    dotnet list package --include-transitive | findstr /i "System.Text.Json"
    # Linux/macOS系统
    dotnet list package --include-transitive | grep -i "System.Text.Json"
    
  • 查看详细restore日志,获取完整依赖链:
    # Windows系统
    dotnet restore --verbosity detailed | findstr /i "System.Text.Json"
    # Linux/macOS系统
    dotnet restore --verbosity detailed | grep -i "System.Text.Json"
    
    注意:还要检查引用的Common.csproj、Core.csproj、Model.csproj这三个项目,它们可能自身依赖了旧版本的System.Text.Json。

第二步:强制全局使用高版本

1. 在.csproj中锁死版本

修改PackageReference配置,强制覆盖所有间接依赖:

<ItemGroup>
  <PackageReference Include="System.Text.Json" Version="9.0.3">
    <PrivateAssets>all</PrivateAssets>
    <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
  </PackageReference>
</ItemGroup>

或者在项目的<PropertyGroup>中添加全局版本变量,统一所有依赖的版本:

<PropertyGroup>
  <TargetFramework>net8.0</TargetFramework>
  <!-- 全局指定System.Text.Json版本 -->
  <SystemTextJsonVersion>9.0.3</SystemTextJsonVersion>
</PropertyGroup>

2. 用NuGet.config做绑定重定向

在项目根目录的NuGet.config中添加以下配置,将所有旧版本请求重定向到9.0.3:

<configuration>
  <runtime>
    <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">
      <dependentAssembly>
        <assemblyIdentity name="System.Text.Json" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />
        <bindingRedirect oldVersion="0.0.0.0-9.0.3.0" newVersion="9.0.3.0" />
      </dependentAssembly>
    </assemblyBinding>
  </runtime>
</configuration>

3. 清理本地NuGet缓存

本地缓存残留的旧包可能导致restore异常,先清理再重试:

dotnet nuget locals all --clear

之后重新执行dotnet restore。

4. 同步更新引用项目的依赖

确保Common、Core、Model三个项目也将System.Text.Json升级到9.0.3版本,避免它们的依赖拉低版本。

内容的提问来源于stack exchange,提问作者Viktor Stjärne

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 23:17:32