Skip to content

Renovate lockfile maintenance #3688

@ianlewis

Description

@ianlewis

Renovate doesn't seem to update transitive dependencies unless a direct dependency is updated. This means some transitive dependencies with vulnerabilities could go a while before being updated.

https://docs.renovatebot.com/configuration-options/#lockfilemaintenance

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:toolingAn issue with project tooling and configtype:featureNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions