dependabot / dependabot/dependabot-core
Pre-release or deleted releases of Action workflows are suggested by Dependabot
- Dominant language
- Ruby
- Stars
- 5.8k
- Forks
- 1.5k
- Avg merge
- 2d 18h
- Merged PRs (30d)
- 149
Description
### Is there an existing issue for this?
- [X] I have searched the existing issues
### Package ecosystem
Actions
### Package manager version
_No response_
### Language version
_No response_
### Manifest location and content before the Dependabot update
_No response_
### dependabot.yml content
_No response_
### Updated dependency
_No response_
### What you expected to see, versus what you actually saw
I created a release for an action (https://github.com/Kleidukos/get-tested/) that was buggy. I then listed it as pre-release, so the previous one was the last one. I then also removed the release altogether, but Dependabot kept opening PRs to suggest the upgrade.
I understand that Actions' versions use git tags, but we also have ways to mark a Release as not being ready for prime time.
Could the release status be taken into account for not propagating the update sequence? (This seems to be the most low-tech option, I'm not wedded to this particular implementation).
### Native package manager behavior
_No response_
### Images of the diff or a link to the PR, issue, or logs
_No response_
### Smallest manifest that reproduces the issue
_No response_
Contributor guide
Research direction
The report names no manifest, Dependabot configuration, source file, or test. Start by reproducing the behavior with the linked action and inspect how Actions tags and release metadata are selected; done means pre-release or deleted releases no longer drive suggested update PRs, with regression coverage for that behavior.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100