dependabot / dependabot/dependabot-core
.NET global tools are no longer being updated
- Dominant language
- Ruby
- Stars
- 5.8k
- Forks
- 1.5k
- Avg merge
- 2d 18h
- Merged PRs (30d)
- 149
Description
### Is there an existing issue for this?
- [x] I have searched the existing issues
### Package ecosystem
NuGet
### Package manager version
_No response_
### Language version
_No response_
### Manifest location and content before the Dependabot update
https://github.com/App-vNext/Polly/blob/708b02b0a6e4721103f6115c7fcc38acbef05103/.config/dotnet-tools.json
### dependabot.yml content
https://github.com/App-vNext/Polly/blob/main/.github/dependabot.yml
### Updated dependency
None.
### What you expected to see, versus what you actually saw
Dependabot should have generated PRs to update the following tools:
- dotnet-stryker 4.7.0 ➡️ 4.8.0
- MartinCostello.WaitForNuGetPackage 1.1.0 ➡️ 1.1.2
- sign 0.9.1-beta.25228.1 ➡️ 0.9.1-beta.25379.1
The last PR we had that updated a tool was on May 1st: https://github.com/App-vNext/Polly/pull/2608
### Native package manager behavior
_No response_
### Images of the diff or a link to the PR, issue, or logs
https://github.com/App-vNext/Polly/actions/runs/17159446769/job/48684648621
### Smallest manifest that reproduces the issue
_No response_
Contributor guide
Research direction
Start by comparing the repository's .config/dotnet-tools.json manifest with .github/dependabot.yml, then inspect the linked GitHub Actions run and the NuGet/.NET global-tools handling in Dependabot. Done means identifying why these tools are skipped and confirming that updates for dotnet-stryker, MartinCostello.WaitForNuGetPackage, and sign can generate PRs.
Written by the indexing model from the issue text.
Assessment
- Domain
- devtools, tooling
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100