dependabot / dependabot/dependabot-core

go.mod: Support updating non-release git dependencies

Open
#2,028 10 comments 14 reactions 0 assignees View on GitHub
L: go:modules T: feature-request
Dominant language
Ruby
Stars
5.8k
Forks
1.5k
Avg merge
2d 18h
Merged PRs (30d)
149

Description

Empirically, dependabot only seems to send PRs to update dependencies that have tags in git. I've also got a bunch of dependencies that point at git repos, and I'd like PRs updating them as well! In other languages, git based dependencies appear to get updated.

Contributor guide

Open the contributing guide

Research direction

The issue describes updating Go dependencies that point to non-release Git revisions, but it names no files, tests, or entry points. Start by locating the Go dependency updater and its existing handling of tagged Git dependencies; done means reliably proposing updates for non-release Git dependencies with coverage for the behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
tooling
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.