dependabot / dependabot/dependabot-core
dependabot updating to non-existent nx versions
- Dominant language
- Ruby
- Stars
- 5.8k
- Forks
- 1.5k
- Avg merge
- 2d 18h
- Merged PRs (30d)
- 149
Description
### Is there an existing issue for this?
- [x] I have searched the existing issues
### Package ecosystem
npm
### Package manager version
_No response_
### Language version
_No response_
### Manifest location and content before the Dependabot update
package.json
### dependabot.yml content
_No response_
### Updated dependency
nx from 21.4.1 to 21.8.0
### What you expected to see, versus what you actually saw
dependabot is creating PRs to bump nx from 21.4.1 to 21.8.0 but since after the security incident all versions prior to 21.4.1 have been removed.
[https://github.com/nrwl/nx/security/advisories/GHSA-cxm3-wv7p-598c](https://github.com/nrwl/nx/security/advisories/GHSA-cxm3-wv7p-598c)
### Native package manager behavior
_No response_
### Images of the diff or a link to the PR, issue, or logs
_No response_
### Smallest manifest that reproduces the issue
_No response_
Contributor guide
Research direction
Start with the package.json manifest and reproduce the Dependabot update from nx 21.4.1 to 21.8.0, checking the package registry's available versions and the resulting pull request target. Done means Dependabot no longer proposes an unavailable nx version for this manifest.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- devtools
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100