Packages with vulnerability alerts are excluded from standard grouping #39697
Unanswered
SchroederSteffen
asked this question in
Request Help
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
How are you running Renovate?
A Mend.io-hosted app
Which platform you running Renovate on?
GitHub.com
Which version of Renovate are you using?
No response
Please tell us more about your question or problem
Given the following config:
{ "$schema": "https://docs.renovatebot.com/renovate-schema.json", "extends": [ "config:best-practices", ":enableVulnerabilityAlerts", ":semanticCommits", "group:allNonMajor" ] }Renovate excludes any packages that have active vulnerability alerts and patches from the
all non-majorgroup.In the case of Angular, this causes version conflicts, because their packages need to be updated together.
Examples:
IMO, the normal group
all non-majorshould still be complete, even if there are other pending PRs.I assume Renovate can only assign a specific version to a single PR?
Logs (if relevant)
Logs
Beta Was this translation helpful? Give feedback.
All reactions