We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
yarn
4.6.0
Node.js v18.20.5
Package JSON /web-client/package.json
Private repository. Happy to provide access where required, but it's not generally applicable to this bug.
https://github.com/StileEducation/dev-environment/blob/master/.github/dependabot.yml
MathLive, 0.103.0 to 0.104.0.
The security label applied to the PR, even though it contained both security and non-security updates in one version bump.
No response
Not our repository, but this is an example of the dependency update elsewhere without the label: cortex-js/cortexjs.io#62
Our repository:
I actually suspect this is because of the following line https://github.com/dependabot/dependabot-core/blob/754c5bccfd78917dc28caa1fc1ee12be3207d592/updater/lib/dependabot/updater/operations/create_security_update_pull_request.rb#L25C15-L25C36 which expects to upgrade versions minimally, but this is the minimal version.
The text was updated successfully, but these errors were encountered:
No branches or pull requests
Is there an existing issue for this?
Package ecosystem
yarn
Package manager version
4.6.0
Language version
Node.js v18.20.5
Manifest location and content before the Dependabot update
Package JSON /web-client/package.json
dependabot.yml content
Private repository. Happy to provide access where required, but it's not generally applicable to this bug.
https://github.com/StileEducation/dev-environment/blob/master/.github/dependabot.yml
Updated dependency
MathLive, 0.103.0 to 0.104.0.
What you expected to see, versus what you actually saw
The security label applied to the PR, even though it contained both security and non-security updates in one version bump.
Native package manager behavior
No response
Images of the diff or a link to the PR, issue, or logs
Not our repository, but this is an example of the dependency update elsewhere without the label: cortex-js/cortexjs.io#62
Our repository:
I actually suspect this is because of the following line https://github.com/dependabot/dependabot-core/blob/754c5bccfd78917dc28caa1fc1ee12be3207d592/updater/lib/dependabot/updater/operations/create_security_update_pull_request.rb#L25C15-L25C36 which expects to upgrade versions minimally, but this is the minimal version.
Smallest manifest that reproduces the issue
No response
The text was updated successfully, but these errors were encountered: