Dependabot creates PR for yanked python dependency #4411
Labels
core 🍏
Relates to the dependabot-core library itself
F: dependency-deprecations
Detecting, avoiding or removing deprecated versions
L: python:poetry
Python packages via poetry
T: bug 🐞
Something isn't working
Package ecosystem
pip poetry
Package manager version
poetry 1.1.11
Language version
Python 3.6
Manifest location and content prior to update
https://github.com/h3llrais3r/Auto-Subliminal/blob/development/pyproject.toml
dependabot.yml content
Updated dependency
Bump gitpython from 3.1.18 to 3.1.20
h3llrais3r/Auto-Subliminal#565
What you expected to see, versus what you actually saw
Dependabot not creating a PR for a yanked version.
https://pypi.org/pypi/GitPython/3.1.20/json (marked as yanked)
Native package manager behavior
Images of the diff or a link to the PR, issue or logs
The text was updated successfully, but these errors were encountered: