dependabot / dependabot/dependabot-core

Support for RPM spec files

Open
#847 7 comments 1 reaction 0 assignees View on GitHub
T: feature-request T: new-ecosystem
Dominant language
Ruby
Stars
5.8k
Forks
1.5k
Avg merge
2d 18h
Merged PRs (30d)
149

Description

Hi,

i think it will be a great feature if dependabot could support RPM's spec file.
There are a lot of projects and organizations that keep RPM sources on github, and they can easily benefit from dependabot
Parsing spec file's entries
`Name:`
'Version:'
'Patch*:'
'BuildRequires:'

for name's version, patches (official CVE), versioned buildrequires.

Contributor guide

Open the contributing guide

Research direction

No source file, test, or entry point is named. Start by locating the existing Dependabot file parsers and their tests, then determine how RPM spec fields such as Name, Version, Patch*, and BuildRequires would map to dependency updates. Done means RPM spec files are parsed and supported update behavior is covered by tests.

Written by the indexing model from the issue text.

Assessment

Domain
tooling
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.