Skip to content

Dependabot wrongly closes PR that it believes is no longer needed #12835

@rzhao271

Description

@rzhao271

Is there an existing issue for this?

  • I have searched the existing issues

Package ecosystem

npm

Package manager version

No response

Language version

Node.js

Manifest location and content before the Dependabot update

https://github.com/microsoft/vscode-python/blob/main/package.json
https://github.com/microsoft/vscode-python/blob/main/package-lock.json

dependabot.yml content

https://github.com/microsoft/vscode-python/blob/main/.github/dependabot.yml

Updated dependency

tmp 0.0.33 to 0.2.4

What you expected to see, versus what you actually saw

Expected: Dependabot keeps the bump PR open.
Actual: Dependabot closes the PR even though package-lock.json still contains an outdated version of the dependency.

Native package manager behavior

No response

Images of the diff or a link to the PR, issue, or logs

microsoft/vscode-python#25360

Smallest manifest that reproduces the issue

No response

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions