dependabot / dependabot-core

🤖 Dependabot's core logic for creating update PR's.
https://docs.github.com/en/code-security/dependabot
MIT License
4.44k stars 915 forks source link

Dependabot missing caret signifier for alerts #9757

Open raako71 opened 2 weeks ago

raako71 commented 2 weeks ago

I got this alert: Upgrade protobufjs to fix 1 Dependabot alert in functions/package-lock.json Upgrade protobufjs to version 7.2.5 or later. For example:

"dependencies": { "protobufjs": ">=7.2.5" } "devDependencies": { "protobufjs": ">=7.2.5" }

however my code has: "dependencies": { "protobufjs": "^7.2.5" }