dependabot / dependabot-core

🤖 Dependabot's core logic for creating update PRs.
https://docs.github.com/en/code-security/dependabot
MIT License
4.62k stars 987 forks source link

Dependabot run doesn't time out (hangs) #9392

Closed lprimak closed 5 months ago

lprimak commented 5 months ago

Is there an existing issue for this?

Package ecosystem

maven

Package manager version

N/A

Language version

Java 21

Manifest location and content before the Dependabot update

https://github.com/arquillian/arquillian-extension-drone/network/updates

dependabot.yml content

N/A

Updated dependency

N/A

What you expected to see, versus what you actually saw

Dependabot job hangs and runs forever, cannot cancel

Native package manager behavior

No response

Images of the diff or a link to the PR, issue, or logs

No response

Smallest manifest that reproduces the issue

No response

lprimak commented 5 months ago

timed out after an hour