Proj6013: Disable SDK version roll-forward when using lock files
When a project enables lock files
by setting RestorePackagesWithLockFile to true, the .NET SDK version should
be pinned exactly by setting sdk.rollForward to disable in the
global.json.
Lock files make restores reproducible by recording the exact resolved package graph. Rolling the SDK forward to a different release can alter which target packages are selected and how they are resolved, voiding the guarantees provides by the lock file. To keep restores deterministic, the SDK version must not roll forward when lock files are in use.
Non-compliant
global.json
{
"sdk": {
"version": "10.0.401",
"rollForward": "latestPatch"
}
}
Compliant
global.json
{
"sdk": {
"version": "10.0.401",
"rollForward": "disable"
}
}