dependabot / dependabot-core

🤖 Dependabot's core logic for creating update PRs.
https://docs.github.com/en/code-security/dependabot
MIT License
4.7k stars 1.02k forks source link

Dependabot has opened 4 separate PRs with completely identical changes, to resolve the same advisory #10581

Open torokati44 opened 1 month ago

torokati44 commented 1 month ago

Is there an existing issue for this?

Package ecosystem

npm

Package manager version

No response

Language version

No response

Manifest location and content before the Dependabot update

No response

dependabot.yml content

No response

Updated dependency

No response

What you expected to see, versus what you actually saw

I would have expected just one PR that encompasses the entire dependency subtree bump.

Native package manager behavior

No response

Images of the diff or a link to the PR, issue, or logs

https://github.com/ruffle-rs/ruffle/pull/17855 https://github.com/ruffle-rs/ruffle/pull/17856 https://github.com/ruffle-rs/ruffle/pull/17857 https://github.com/ruffle-rs/ruffle/pull/17858

Smallest manifest that reproduces the issue

No response

torokati44 commented 1 month ago

Actually we got 4 different alerts: https://github.com/ruffle-rs/ruffle/security/dependabot/78 https://github.com/ruffle-rs/ruffle/security/dependabot/79 https://github.com/ruffle-rs/ruffle/security/dependabot/80 https://github.com/ruffle-rs/ruffle/security/dependabot/81