dependabot / dependabot/dependabot-core
[NuGet] Dependabot is adding (injecting) new package reference dependencies
- Dominant language
- Ruby
- Stars
- 5.8k
- Forks
- 1.5k
- Avg merge
- 2d 18h
- Merged PRs (30d)
- 155
Description
### Is there an existing issue for this?
- [x] I have searched the existing issues
### Package ecosystem
NuGet
### Package manager version
_No response_
### Language version
_No response_
### Manifest location and content before the Dependabot update
_No response_
### dependabot.yml content
_No response_
### Updated dependency
_No response_
### What you expected to see, versus what you actually saw
Examples:
* https://github.com/WildGums/Blorc.OpenIdConnect/pull/838
* https://github.com/WildGums/Blorc.OpenIdConnect/pull/837
### Native package manager behavior
_No response_
### Images of the diff or a link to the PR, issue, or logs
_No response_
### Smallest manifest that reproduces the issue
_No response_
Contributor guide
Research direction
Start by reviewing the added package references in linked PRs 838 and 837, then collect the missing dependabot.yml, manifest, package-manager and language versions, and a minimal reproduction. Done means a NuGet update no longer injects unrequested package references, with the behavior covered by an appropriate regression test.
Written by the indexing model from the issue text.
Assessment
- Domain
- tooling
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100