Skip to content

Dependabot is updating more dependencies than it should with npm lockfiles v2 #3182

@DeltaEvo

Description

@DeltaEvo

Package manager/ecosystem
npm
Manifest contents prior to update
https://github.com/aresrpg/aresrpg/blob/65e7017339eeba555d904f7614665ffaecfd8029/package.json
Updated dependency
eslint-plugin-promise
What you expected to see, versus what you actually saw
I expected to see only the eslin-plugin-promise to be updated but instead inside the lockfile a lot of other dependencies where updated and the package.json was not updated
Images of the diff or a link to the PR, issue or logs
aresrpg/aresrpg#141

I also have this one for eslint-config-prettier aresrpg/aresrpg#145 where the package.json have been updated but a lot of other unrelated dependencies have been updated as well

Metadata

Metadata

Assignees

No one assigned

    Labels

    T: bug 🐞Something isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions