Skip to content

pnpm: support v9 lockfile format for dependabot alerts - and/or warn that it is unsupported #10534

@jamescrowley

Description

@jamescrowley

Is there an existing issue for this?

  • I have searched the existing issues

Feature description

There is already an issue for this: #9522 that has been closed, but I've confirmed with GitHub support that in fact it is still not supported for security updates.

We are not seeing any security alerts since upgrading. This seems pretty dangerous given others may also have upgraded without realising they would no longer receive updates - dependabot doesn't seem to trigger any warning for this?

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions