dependabot / dependabot/dependabot-core

Lock file update is broken

Open
#13,474 8 comments 7 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

L: dotnet:nuget T: bug 🐞
Dominant language
Ruby
Stars
5.8k
Forks
1.5k
Avg merge
2d 13h
Merged PRs (30d)
151

Description

Is there an existing issue for this?
  • I have searched the existing issues
Package ecosystem

nuget

Package manager version

No response

Language version

No response

Manifest location and content before the Dependabot update

https://github.com/BluehillNuGet/bluehillnuget.github.io/blob/5ee7e03e0c5ce79af4eda8fece4a6dc8e91d38c3/Directory.Packages.props

dependabot.yml content

https://github.com/BluehillNuGet/bluehillnuget.github.io/blob/bcc6e6696d77f9734213377abbbc268c9ff80be7/.github/dependabot.yml

Updated dependency

No response

What you expected to see, versus what you actually saw

Dependencies of a project using a NuGet lock file should be updated correctly, but for some reason dotnet restore fails.

Native package manager behavior

No response

Images of the diff or a link to the PR, issue, or logs

https://github.com/BluehillNuGet/bluehillnuget.github.io/actions/runs/19093211355/job/54547724198

Smallest manifest that reproduces the issue

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with Directory.Packages.props and .github/dependabot.yml at the linked revisions, then inspect the linked GitHub Actions job for the dotnet restore failure. Reproduce the Dependabot update against the NuGet project and compare the generated lock-file change with a successful restore; done means the update completes and dotnet restore passes.

Written by the indexing model from the issue text.

Assessment

Domain
build-system
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.