Skip to content

Bug: stale-analyzer-include-paths-break-clean-build #936

Description

@drmoisan
  • Work Mode: minor-audit

Summary

main does not compile after a clean package restore. Dependabot PR #921 (merged 2026-09-26) bumped Meziantou.Analyzer to 3.0.290 and MSTest.Analyzers to 4.4.1 in every packages.config, but left the <Analyzer Include> paths in the project files pointing at the previous version folders. A clean restore does not create those folders, so the compiler fails with CS0006. CI stays green because its actions/cache restore-keys fallback restores an older packages/ cache that still contains the stale folders.

Environment

  • OS/version: Windows 11 Pro 10.0.26200
  • Python version: not applicable (.NET Framework 4.8.1 packages.config solution)
  • Command/flags used: msbuild TaskMaster.sln /t:Restore /p:RestorePackagesConfig=true, then msbuild TaskMaster.sln /t:Rebuild /m /p:Configuration=Debug "/p:Platform=Any CPU"
  • Data source or fixture: a fresh detached worktree at main dcce3c816 with an empty packages/ folder

Steps to Reproduce

  1. Create a fresh worktree at main.
  2. Restore packages into its empty packages/ folder.
  3. Rebuild the solution.

Expected Behavior

The solution builds from a clean restore, and CI fails whenever it would not.

Actual Behavior

The build fails with:

  • CSC : error CS0006: Metadata file '..\packages\Meziantou.Analyzer.3.0.235\analyzers\dotnet\roslyn5.0\cs\Meziantou.Analyzer.dll' could not be found, in 16 project files. The manifests declare 3.0.290.
  • CSC : error CS0006: Metadata file '..\packages\MSTest.Analyzers.4.4.0\analyzers\dotnet\cs\MSTest.Analyzers.dll' could not be found, plus MSTest.Analyzers.CodeFixes.dll, in 9 project files. The manifests declare 4.4.1.

A scan of every ..\packages\<dir>\ reference against the clean restore finds exactly these two stale directories. It also finds altcover.8.6.45, which is guarded by Exists() and tracked by #929.

Logs / Screenshots

  • Attached minimal logs or screenshot
  • Snippet: see Actual Behavior. The fix commit records the before and after rebuild output.

Impact / Severity

  • Blocker
  • High
  • Medium
  • Low

Blocker: the maintainer cannot build the tool from a clean checkout. Every fresh worktree used by agent runs is affected as well.

Source

From: docs/features/potential/2026-09-29-stale-analyzer-include-paths-break-clean-build.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions