dependabot / dependabot/dependabot-core

Dependabot sent a PR to update pip for a directory outside what's configured in dependabot.yml

Open
#14,864 0 comments 0 reactions 1 assignee Claimed by @v-robaiken View on GitHub
L: bazel L: python T: bug 🐞
Dominant language
Ruby
Stars
5.8k
Forks
1.5k
Avg merge
2d 18h
Merged PRs (30d)
149

Description

### Is there an existing issue for this?

- [x] I have searched the existing issues

### Package ecosystem

pip

### Package manager version

_No response_

### Language version

_No response_

### Manifest location and content before the Dependabot update

_No response_

### dependabot.yml content

https://github.com/bazelbuild/bazel-central-registry/blob/77b66b7519e6d8fb3634ef78c0f4d643561289ce/.github/dependabot.yml

### Updated dependency

_No response_

### What you expected to see, versus what you actually saw

dependabot.yml says to only update pip dependencies under `/tools`. But dependabot sent a PR to update requirements.txt files under `/modules/nanobind/2.12.0/overlay/tests` and `/modules/nanobind/2.9.2/overlay/tests`.

### Native package manager behavior

_No response_

### Images of the diff or a link to the PR, issue, or logs

https://github.com/bazelbuild/bazel-central-registry/pull/8540

### Smallest manifest that reproduces the issue

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.