The package manager decides which packages are used based on how dependencies are specified. For example, you might ask for library-A >= 1.1, but a transitive dependency specification (a dependency of a dependency) may specify library-A >= 1.0 && <= 1.6. If versions up to 1.7 are available, you'd probably get 1.6. Probably. Because with some package managers, if you have version 1.5 sitting around in a local cache, it may use that instead.
Basically, never try to guess what the package manager is going to resolve. Just let it do its job, just as it does for your production builds, and use that information to look up any associated vulnerabilities.