Skip to content

[BUG] Dependency Review reports the Vulnerability which we are updating. #830

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
Shweta4398 opened this issue Sep 22, 2024 · 2 comments
Closed
Labels
bug Something isn't working Stale

Comments

@Shweta4398
Copy link

Describe the bug
Hello ,

I had a quick question , if the changes are made to package.json file does dependency scans for lock file as well ?? But in the PR there is no changes made to the lock file.

Here , we saw an issue with there was a PR raised by dependabot to bump the body parser version from 1.20.2 to 1.20.3 . PR is making the change but the dependency review check is failing here , I don't understand why ??

Please find the attach screenshots!!
Screenshot 2024-09-22 at 5 37 21 PM
Screenshot 2024-09-22 at 5 38 38 PM
Screenshot 2024-09-22 at 5 38 11 PM

To Reproduce
Steps to reproduce the behavior:

  1. Go to '...'
  2. Click on '....'
  3. Scroll down to '....'
  4. See error

Expected behavior
A clear and concise description of what you expected to happen.

Screenshots
If applicable, add screenshots to help explain your problem.

Action version
What version of the action are you using in your workflow?

Note: if you're not running the latest release please try that first!

Examples
If possible, please link to a public example of the issue that you're encountering, or a copy of the workflow that you're using to run the action.

If you have encountered a problem with a specific package (e.g. issue with license or attributions data) please share details about the package, as well as a link to the manifest where it's being referenced.

Additional context
Add any other context about the problem here.

@Shweta4398 Shweta4398 added the bug Something isn't working label Sep 22, 2024
Copy link

👋 This issue has been marked as stale because it has been open with no activity for 180 days. You can: comment on the issue or remove the stale label to hold stalebot off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing, this issue will be closed eventually by the stalebot. Please see CONTRIBUTING.md for more policy details.

@github-actions github-actions bot added the Stale label Mar 22, 2025
Copy link

github-actions bot commented Apr 6, 2025

👋 This issue has been closed by stalebot because it has been open with no activity for over 180 days. Please see CONTRIBUTING.md for more policy details.

@github-actions github-actions bot closed this as not planned Won't fix, can't repro, duplicate, stale Apr 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working Stale
Projects
None yet
Development

No branches or pull requests

1 participant