Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot reports non-existent NuGet update in PR description that is also a downgrade #11306

Open
1 task done
martincostello opened this issue Jan 15, 2025 · 0 comments
Open
1 task done
Labels
T: bug 🐞 Something isn't working

Comments

@martincostello
Copy link
Contributor

Is there an existing issue for this?

  • I have searched the existing issues

Package ecosystem

NuGet

Package manager version

No response

Language version

No response

Manifest location and content before the Dependabot update

martincostello/costellobot@693cdf4

dependabot.yml content

https://github.com/martincostello/costellobot/blob/693cdf4e20e8ac89359f162c9e44cc0e29c5f62f/.github/dependabot.yml

Updated dependency

martincostello/costellobot#1953

  • Azure.Identity 1.13.1 to 1.13.2
  • System.Text.Json 9.0.1 to 6.0.10

What you expected to see, versus what you actually saw

The pull request description claims to have updated Azure.Identity and System.Text.Json.

Viewing the diff shows that System.Text.Json has not been upgraded at all.

The pull request also claims that the package has been downgraded:

Updates System.Text.Json from 9.0.1 to 6.0.10

Dependabot should not include System.Text.Json in the PR/commit description at all as it was not updated, but should also not be trying to downgrade packages.

Native package manager behavior

No response

Images of the diff or a link to the PR, issue, or logs

martincostello/costellobot#1953

Smallest manifest that reproduces the issue

No response

@martincostello martincostello added the T: bug 🐞 Something isn't working label Jan 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
T: bug 🐞 Something isn't working
Projects
Status: No status
Development

No branches or pull requests

1 participant