dependabot / dependabot/dependabot-core

Wrongly closing PRs as "dependency no longer updateable", when nothing has changed since the last run

Open
#10,465 9 comments 8 reactions 0 assignees View on GitHub
L: go:modules L: rust:cargo T: bug 🐞
Dominant language
Ruby
Stars
5.8k
Forks
1.5k
Avg merge
2d 18h
Merged PRs (30d)
149

Description

### Is there an existing issue for this?

- [X] I have searched the existing issues

### Package ecosystem

cargo

### Package manager version

_No response_

### Language version

_No response_

### Manifest location and content before the Dependabot update

_No response_

### dependabot.yml content

_No response_

### Updated dependency

_No response_

### What you expected to see, versus what you actually saw

https://github.com/ruffle-rs/ruffle/pull/17567#issuecomment-2297369877 and https://github.com/ruffle-rs/ruffle/pull/16835#issuecomment-2297369714 were closed, when they shouldn't have been.

### Native package manager behavior

_No response_

### Images of the diff or a link to the PR, issue, or logs

_No response_

### Smallest manifest that reproduces the issue

_No response_

Contributor guide

Open the contributing guide

Research direction

Start with the two referenced Ruffle pull requests and their linked comments, then trace the Dependabot run that classified them as “dependency no longer updateable.” Confirm the behavior with a Cargo update case where nothing changed; done means unchanged dependencies are not incorrectly closed for that reason.

Written by the indexing model from the issue text.

Assessment

Tech stack
ruby, rust
Domain
tooling
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.