dependabot / dependabot/dependabot-core

dependabot updating to non-existent nx versions

Open
#12,959 0 comments 0 reactions 0 assignees View on GitHub
L: javascript T: bug 🐞
Dominant language
Ruby
Stars
5.8k
Forks
1.5k
Avg merge
2d 18h
Merged PRs (30d)
149

Description

### Is there an existing issue for this?

- [x] I have searched the existing issues

### Package ecosystem

npm

### Package manager version

_No response_

### Language version

_No response_

### Manifest location and content before the Dependabot update

package.json

### dependabot.yml content

_No response_

### Updated dependency

nx from 21.4.1 to 21.8.0

### What you expected to see, versus what you actually saw

dependabot is creating PRs to bump nx from 21.4.1 to 21.8.0 but since after the security incident all versions prior to 21.4.1 have been removed.
[https://github.com/nrwl/nx/security/advisories/GHSA-cxm3-wv7p-598c](https://github.com/nrwl/nx/security/advisories/GHSA-cxm3-wv7p-598c)

### Native package manager behavior

_No response_

### Images of the diff or a link to the PR, issue, or logs

_No response_

### Smallest manifest that reproduces the issue

_No response_

Contributor guide

Open the contributing guide

Research direction

Start with the package.json manifest and reproduce the Dependabot update from nx 21.4.1 to 21.8.0, checking the package registry's available versions and the resulting pull request target. Done means Dependabot no longer proposes an unavailable nx version for this manifest.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
devtools
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.