-
Notifications
You must be signed in to change notification settings - Fork 1.3k
Closed
Labels
Description
- I've committed a
package.jsonwith a library subdirectory included in my project (not using package manager for this project). - Dependabot reported a security alert.
- I've deleted the
package.jsonand thought that it would resolve it.
But I'm still getting the alert listed in my daily e-mail notification (and in the list of alerts on repository Security page). I've tried to dismiss the alert with "A fix has already been started", didn't change anything.
The alert page further shows a warning message "Dependabot cannot update this dependency" detailed as "Dependabot couldn't update this dependency to the required version as it doesn't support your dependency files.".
meuxx, sambdavidson, rob4629, carlgunderson, xdaDaveShaw and 71 more