dependabot / dependabot/dependabot-core

Ignore unstable semver versions

Open
#8,677 4 comments 6 reactions 0 assignees View on GitHub
T: feature-request
Dominant language
Ruby
Stars
5.8k
Forks
1.5k
Avg merge
2d 18h
Merged PRs (30d)
149

Description

### Is there an existing issue for this?

- [X] I have searched the existing issues

### Feature description

Currently Dependabot seems [only able to ignore major, minor and patch version](https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#specifying-dependencies-and-versions-to-ignore). Would it be possible to ignore unstable versions, built by adding extensions to the semver versions, such as prereleases?

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or entry points. Start by tracing Dependabot's dependency-version ignore configuration and semver handling, then establish expected behavior for prerelease versions and identify the relevant test coverage before estimating the change.

Written by the indexing model from the issue text.

Assessment

Tech stack
ruby
Domain
tooling
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.