-
Notifications
You must be signed in to change notification settings - Fork 1.3k
Closed
Labels
Description
Is there an existing issue for this?
- I have searched the existing issues
Package ecosystem
npm
Package manager version
pnpm 10
Language version
No response
Manifest location and content before the Dependabot update
pnpm-workspace.yamlpnpm-lock.yamlpackage.jsonextension/package.jsonpackages/git/package.jsonbuild_defs/rollup_bundle/package.jsonbuild_defs/vsce_package/package.json
dependabot.yml content
Updated dependency
rollup from 4.34.8 to 4.34.9.
@types/node from 22.13.7 to 22.13.8 (issue observed in 2 PRs, the merge commit for this applied the downgrade to main branch, note this particular change is also affected by #11837).
What you expected to see, versus what you actually saw
Hash for patched dependency watcher@2.3.1 to be untouched.
Native package manager behavior
Untouched SHA256 hash for watcher@2.3.1 (prior to pnpm v9 this was an MD5 hash).
Images of the diff or a link to the PR, issue, or logs
Silic0nS0ldier/vscode-git-monolithic-extension#90
Silic0nS0ldier/vscode-git-monolithic-extension#89 (downgrade merged here)
Smallest manifest that reproduces the issue
lishaduck
Metadata
Metadata
Assignees
Labels
Type
Projects
Status
Done