dependabot / dependabot/dependabot-core

Allow/Ignore specific manifests

Open
#2,883 10 comments 38 reactions 0 assignees View on GitHub
F: configuration-file F: dependency-ignores Keep T: feature-request
Dominant language
Ruby
Stars
5.8k
Forks
1.5k
Avg merge
2d 18h
Merged PRs (30d)
149

Description

Wanted to bring up this issue again: https://github.com/dependabot/dependabot-core/issues/1629 which got closed due to no response.

Having an option to inspect specific files would make configuration a lot easier. In my case, we have multiple requirements.txt files all in the same directory, but we want to inspect just one of these requirements files.

Contributor guide

Open the contributing guide

Research direction

Start by reading issue #1629 and tracing how Dependabot selects requirements.txt manifests when multiple files share a directory. No implementation files or tests are named in this issue; done means configuration can target only the specified manifest while preserving normal dependency inspection behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
devops
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.