Renovate does not recognize Drupal security releases as security updates #22918
-
How are you running Renovate?Mend Renovate hosted app on github.com If you're self-hosting Renovate, tell us what version of Renovate you run.N/A If you're self-hosting Renovate, select which platform you are using.None Was this something which used to work for you, and then stopped?I am trying to get this working for the first time Describe the problemhttps://docs.renovatebot.com/configuration-options/#prconcurrentlimit says:
For Drupal Core or contrib modules, those are rate limited, and do not have [SECURITY] in the PR title. For example, https://www.drupal.org/project/office_hours/releases/8.x-1.11 was rate limited, we checked the checkbox to manually create the PR, and the PR title appeared like: "Update dependency drupal/office_hours to ^1.11.0" Maybe there is no fix for renovate? Maybe the fix needs to come from drupal infrastructure, like this issue: d.o 3301876: Implement “list security advisories” Packagist/Composer API Relevant debug logsLogs
I'll attempt to make a minimal reproduction repo. Have you created a minimal reproduction repository?I have explained in the description why a minimal reproduction is impossible |
Beta Was this translation helpful? Give feedback.
Replies: 6 comments 1 reply
-
Can be explained by the fact that sa-contrib-2023-020 is a security advisory you find only on Drupal's website. The underlying vulnerability has no CVE identifier assigned and is unknown to common vulnerability databases, incl the sources that renovate relies upon. |
Beta Was this translation helpful? Give feedback.
This comment was marked as off-topic.
This comment was marked as off-topic.
This comment was marked as off-topic.
This comment was marked as off-topic.
-
There has been a change to drupal.org meta data about security releases. https://www.drupal.org/project/project_composer/issues/3301876#comment-15240460 I'm not certain yet if that is sufficient for renovate to start picking up the drupal security releases as security releases. |
Beta Was this translation helpful? Give feedback.
-
Can renovate get the security info by running https://packagist.org/apidoc#list-security-advisories with packages.drupal.org/8 ?? |
Beta Was this translation helpful? Give feedback.
-
Hi there, Get your discussion fixed faster by creating a minimal reproduction. This means a repository dedicated to reproducing this issue with the minimal dependencies and config possible. Before we start working on your issue we need to know exactly what's causing the current behavior. A minimal reproduction helps us with this. Discussions without reproductions are less likely to be converted to Issues. Please follow these steps:
Good luck, The Renovate team |
Beta Was this translation helpful? Give feedback.
Can be explained by the fact that sa-contrib-2023-020 is a security advisory you find only on Drupal's website. The underlying vulnerability has no CVE identifier assigned and is unknown to common vulnerability databases, incl the sources that renovate relies upon.