Dependabot security updates for multiple branches #15027
Replies: 5 comments 3 replies
-
It took me a lot of time to figure out that I would suggest that meanwhile this feature is not supported, at least update the documentation of #target-branch to have a warning about this behavior so that it's clear the current limitations. |
Beta Was this translation helpful? Give feedback.
-
We also ran into this problem and wasted time debugging it. Would be great if we could get security updates towards |
Beta Was this translation helpful? Give feedback.
-
I couldn't find an open issue on https://github.com/dependabot/dependabot-core, do you happen to know where this feature/issue can be tracked ? |
Beta Was this translation helpful? Give feedback.
-
Building two docker images of the same tool, on two different versions, hits this problem. But this does not work, e.g. nothing happens in the |
Beta Was this translation helpful? Give feedback.
-
It seems like it's working as expected, an example config and the PRs opened against "v0.11" branch (did not check if they are really only security updates but if you change the base to "master" there are more updates - e.g. grpc 1.51.0 to 1.52.0) |
Beta Was this translation helpful? Give feedback.
-
Currently, Dependabot only performs security updates against the default branch. However, a project may have multiple active branches that still need security updates. Need a way to configure Dependabot to also scan certain branches for security updates.
Note that Dependabot version updates supports multiple branches using
target-branch
independabot.yml
, but that configuration is not used for security updates.Beta Was this translation helpful? Give feedback.
All reactions