# XO1317: a dependency's effects are wider than xo.lock records

xo.lock records, for every required module, the effects its exported API can reach: a line `<module path> effects <labels|none>`, the union of the `uses` of its pub functions and methods. `xo get` and `xo mod tidy` write it the first time a module is locked, and narrow it when a version needs less. When the selected version needs an effect the line does not admit (an update that starts using `net`, `proc`, `log`, ...), every command that loads the program fails with this error, and `xo get` and `xo mod tidy` write nothing. Review why the dependency now needs the effect. To accept it, run `xo mod accept-effects <module path>` (or `xo get --accept-effects <path>@<version>`); the change is an xo.lock diff a reviewer sees. Otherwise stay on the previous version. See core 4.3 and decision 0156.

## Example

```xo
# xo.lock: github.com/acme/billing effects none
xo get github.com/acme/billing@v1.5.0   # v1.5.0 declares uses net.dial
```

## Fix

```xo
# after review:
xo mod accept-effects github.com/acme/billing
```

Run `xo explain XO1317` for this text in a terminal, or see
[section 10.6 of the specification](../../spec/core/#106-diagnostic-codes).

