Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix updating lockfile in dependabot PRs #283

Open
fhlavac opened this issue Jan 29, 2025 · 0 comments
Open

Fix updating lockfile in dependabot PRs #283

fhlavac opened this issue Jan 29, 2025 · 0 comments
Labels
bug Something isn't working

Comments

@fhlavac
Copy link
Collaborator

fhlavac commented Jan 29, 2025

Currently, there is an issue in PRs opened by dependabot

  • when a dependency is updated in package.json, the change is not reflected in the package-lock.json - merging such PRs may be dangerous as the CI is not actually running with the updated version of the dependency
  • PRs updating only dependencies listed in the package-lock.json file look correct

clone of #patternfly/react-component-groups#557

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
Status: Needs triage
Development

No branches or pull requests

1 participant