Azure DevOps Server compatibility
The extension targets REST API version 6.1 — the maximum supported by Azure DevOps Server 2020 — so it works on both on-premises Server installs and hosted Azure DevOps. To preserve this, the build pins azure-devops-extension-api to the v1 line; v2 and every later major of that package default to REST api-version=7.2, which Server 2020 rejects with a 400. 1.158.0 is the final v1 release, so this is a ceiling rather than a version we have fallen behind on, and the extension manifest declares a matching api-version/5.1 demand.
azure-devops-extension-sdk is pinned at 2.0.11 as a direct consequence of that, not as a separate decision. azure-devops-extension-api@1.158.0 declares the SDK as a hard dependency at ~2.0.11 and calls into it, so raising the SDK on its own makes npm install a second copy nested underneath the API. The SDK refuses to initialise twice — it guards on a _AzureDevOpsSDKVersion global — and two copies in one bundle means two message channels to the Azure DevOps host and a broken handshake. Both pins therefore move together, and only if on-premises Server support is dropped.