Skip to content

Support pnpm up to the newest versions #13874

@TheCoreMan

Description

@TheCoreMan

Is there an existing issue for this?

  • I have searched the existing issues

Feature description

We use pnpm on version 10.22.0, and when dependabot reports a vuln in one of our dependencies, it shows that it can't support creating a PR on it - with "pnpm version not supported"

Right now (at time of writing):

  1. Docs state that pnpm 10 is supported (here: https://docs.github.com/en/code-security/dependabot/ecosystems-supported-by-dependabot/supported-ecosystems-and-repositories)
Image
  1. Newest pnpm version is 10.27.0 (released yesterday). https://github.com/pnpm/pnpm/releases/tag/v10.27.0

Our current workaround is creating manual PRs with pnpm audit --fix or other manual upgrades.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions