Detect and resolve package dependency conflicts before installation across npm/yarn/pnpm, pip/poetry, cargo, and composer. Auto-trigger when installing/upgrading packages...
[CONFLICT DETECTED] Package: react@18.0.0 Conflict: react-dom@17.0.0 requires react ^17.0.0 Risk: MEDIUM (breaking change)
[RECOMMENDED ACTION] Option 1: Upgrade react-dom to ^18.0.0 (recommended) npm install react@18.0.0 react-dom@18.0.0
Option 2: Downgrade react to ^17.0.0 npm install react@17.0.0
[SECURITY CHECK] ā No known vulnerabilities in react@18.0.0 ā No known vulnerabilities in react-dom@18.0.0
</quick_example>
</quick_start>
<workflow>
<detection_phase>
**1. Identify Package Manager and Context**
Scan current directory for lockfiles and package manifests:
- **JavaScript**: package.json + (package-lock.json | yarn.lock | pnpm-lock.yaml)
- **Python**: requirements.txt | Pipfile | pyproject.toml + (Pipfile.lock | poetry.lock)
- **Rust**: Cargo.toml + Cargo.lock
- **PHP**: composer.json + composer.lock
Extract:
- Current dependency versions (from lockfile)
- Requested package and version (from user command)
- Version constraints (from manifest)
</detection_phase>
<conflict_analysis>
**2. Analyze Dependency Conflicts**
Check for conflicts in order of severity:
**A. Peer Dependency Conflicts**
- Compare requested version against peer dependency requirements
- Identify which packages will be incompatible
- Calculate semver compatibility ranges
**B. Transitive Dependency Conflicts**
- Build dependency graph of all transitive dependencies
- Detect duplicate packages with incompatible versions
- Identify shared dependencies requiring specific versions
**C. Version Constraint Violations**
- Validate against existing version constraints in manifest
- Check for semver range compatibility (^, ~, >=, etc.)
- Detect locked versions that prevent resolution
**D. Platform/Runtime Conflicts**
- Check Node.js, Python, PHP version requirements
- Validate feature flags (Rust features)
- Check platform-specific dependencies
</conflict_analysis>
<security_audit>
**3. Security Vulnerability Scan**
Run ecosystem-specific security audits:
**JavaScript (npm/yarn/pnpm):**
```bash
npm audit --json
# Parse output for HIGH/CRITICAL vulnerabilities
# Check: GHSA IDs, CVE numbers, severity scores
Python (pip/poetry):
pip-audit --format json
# Or: poetry audit --json
# Parse PyPA Advisory Database results
Rust (cargo):
cargo audit --json
# Check RustSec Advisory Database
# Identify RUSTSEC-YYYY-NNNN advisories
PHP (composer):
composer audit --format json
# Parse security advisories
# Check for blocked insecure packages
For each vulnerability found:
Auto-resolve (apply without asking):
Suggest manual review (present options):
Block with alternatives (prevent installation):
Resolution output format:
[CONFLICT TYPE] Brief description
Package: package-name@requested-version
Current: package-name@current-version
Conflict: dependency-name requires version-constraint
[IMPACT ASSESSMENT]
Risk: LOW | MEDIUM | HIGH | CRITICAL
Scope: dev-only | production | peer-dependency | transitive
[RECOMMENDED ACTIONS]
1. [Primary recommendation with command]
2. [Alternative approach with tradeoffs]
3. [Fallback option if applicable]
[SECURITY STATUS]
ā No vulnerabilities | ā Vulnerabilities found (details below)
For auto-resolvable conflicts:
For manual review conflicts:
For blocking conflicts:
Common conflict patterns:
Resolution tools:
npm ls <package> - Show dependency tree for packagenpm why <package> - Explain why package is installednpm audit fix - Auto-fix vulnerabilitiesnpm overrides (package.json) - Force specific versions globallySee references/javascript-patterns.md for detailed examples.
Python (pip/poetry)
Common conflict patterns:
Resolution tools:
pip check - Verify installed packages have compatible dependenciespip install --dry-run - Simulate installation without applyingpoetry show --tree - Display dependency treepoetry update --dry-run - Preview updates without applyingSee references/python-patterns.md for detailed examples.
Rust (cargo)
Common conflict patterns:
Resolution tools:
cargo tree -d - Show duplicate dependenciescargo tree -i <package> - Show inverse dependenciescargo update --dry-run - Preview updatescargo outdated - Check for newer versionsSee references/rust-patterns.md for detailed examples.
PHP (composer)
Common conflict patterns:
Resolution tools:
composer why <package> - Show why package is installedcomposer why-not <package> <version> - Explain why version can't be installedcomposer outdated - List available updatescomposer audit - Security vulnerability scanSee references/php-patterns.md for detailed examples.
Understand version constraint symbols:
^1.2.3 ā >=1.2.3 <2.0.0 (compatible changes)~1.2.3 ā >=1.2.3 <1.3.0 (patch updates only)>=1.2.3 <2.0.0 ā Explicit range1.2.x ā Any patch version in 1.2.x* ā Any version (avoid in production)Lockfile Strategy:
npm ci / poetry install in CI/CD (installs exact versions)Monorepo Considerations:
Security Best Practices:
See references/advanced-resolution.md for complex scenarios.
1. Blindly using --force or --legacy-peer-deps
2. Ignoring security warnings
3. Using wildcard versions (*) in production
4. Deleting lockfiles to "fix" conflicts
5. Installing packages without checking compatibility
6. Mixing package managers (npm + yarn)
7. Upgrading all dependencies at once
8. Using outdated audit tools
Blocked installation when: