-
Notifications
You must be signed in to change notification settings - Fork 1.3k
Open
Labels
Description
Is there an existing issue for this?
- I have searched the existing issues
Feature description
We use pnpm on version 10.22.0, and when dependabot reports a vuln in one of our dependencies, it shows that it can't support creating a PR on it - with "pnpm version not supported"
Right now (at time of writing):
- Docs state that pnpm 10 is supported (here: https://docs.github.com/en/code-security/dependabot/ecosystems-supported-by-dependabot/supported-ecosystems-and-repositories)
- Newest pnpm version is
10.27.0(released yesterday). https://github.com/pnpm/pnpm/releases/tag/v10.27.0
Our current workaround is creating manual PRs with pnpm audit --fix or other manual upgrades.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Type
Projects
Status
No status