Skip to content

Renovate not create PRs for vulnerabilityAlerts #22747

Discussion options

You must be logged in to vote

There are two vulnerability alerts, both are indirect/transitive dependencies (in the lock file, not Pipfile).

Looking at the two Dependabot PRs, they seem identical and seem to be a full lockfile refresh rather than anything targeted. You can achieve the same with Renovate by enabling the "lockFileMaintenance" feature.

Replies: 1 comment 5 replies

Comment options

You must be logged in to vote
5 replies
@MaxymVlasov
Comment options

@rarkins
Comment options

@MaxymVlasov
Comment options

@MaxymVlasov
Comment options

@rarkins
Comment options

Answer selected by MaxymVlasov
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants