Security update MR not created for unconstraint uv dependencies #36541
Unanswered
cd-fge
asked this question in
Request Help
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
How are you running Renovate?
Self-hosted Renovate
If you're self-hosting Renovate, tell us which platform (GitHub, GitLab, etc) and which version of Renovate.
GitLab
Please tell us more about your question or problem
For the Python uv package manager renovate only creates security update MRs when the dependency has a version constraint.
For example with this pyproject.toml and
requests2.32.3 in the uv.lock file, renovate won't create a MR to upgrade requests for GHSA-9hjg-9r4m-mvj7.However when adding a version constraint for requests it will create a MR:
Renovate config used:
Logs (if relevant)
Logs no version contraint
Logs with version contraint
Beta Was this translation helpful? Give feedback.
All reactions