dependabot / dependabot/dependabot-core
Lock file update is broken
Nobody has claimed this yet.
- Dominant language
- Ruby
- Stars
- 5.8k
- Forks
- 1.5k
- Avg merge
- 2d 13h
- Merged PRs (30d)
- 151
Description
Is there an existing issue for this?
- I have searched the existing issues
Package ecosystem
nuget
Package manager version
No response
Language version
No response
Manifest location and content before the Dependabot update
dependabot.yml content
Updated dependency
No response
What you expected to see, versus what you actually saw
Dependencies of a project using a NuGet lock file should be updated correctly, but for some reason dotnet restore fails.
Native package manager behavior
No response
Images of the diff or a link to the PR, issue, or logs
https://github.com/BluehillNuGet/bluehillnuget.github.io/actions/runs/19093211355/job/54547724198
Smallest manifest that reproduces the issue
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with Directory.Packages.props and .github/dependabot.yml at the linked revisions, then inspect the linked GitHub Actions job for the dotnet restore failure. Reproduce the Dependabot update against the NuGet project and compare the generated lock-file change with a successful restore; done means the update completes and dotnet restore passes.
Written by the indexing model from the issue text.
Assessment
- Domain
- build-system
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100