Dependabot grouped security update PRs ignore labels from dependabot.yml #184930
Replies: 2 comments
-
|
This warning is due to a recent change in how GitHub Actions validates expressions. Expressions must now be fully contained inside a single So this form is now discouraged: if: endsWith(${{ needs.precheck.outputs.version }}, '-SNAPSHOT')The correct and recommended form is: if: ${{ endsWith(needs.precheck.outputs.version, '-SNAPSHOT') }}This is not a breaking change in behavior, just stricter syntax validation to prevent subtle logic bugs. Updating conditions this way will silence the warning and keep workflows future-proof. |
Beta Was this translation helpful? Give feedback.
-
|
🕒 Discussion Activity Reminder 🕒 This Discussion has been labeled as dormant by an automated system for having no activity in the last 60 days. Please consider one the following actions: 1️⃣ Close as Out of Date: If the topic is no longer relevant, close the Discussion as 2️⃣ Provide More Information: Share additional details or context — or let the community know if you've found a solution on your own. 3️⃣ Mark a Reply as Answer: If your question has been answered by a reply, mark the most helpful reply as the solution. Note: This dormant notification will only apply to Discussions with the Thank you for helping bring this Discussion to a resolution! 💬 |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi everyone 👋
I’m running into what looks like either a Dependabot limitation or a bug related to grouped security update pull requests not receiving labels, even though labels are clearly configured in
dependabot.yml.Context
groupsfeatureapplies-to: security-updatesHere is a simplified excerpt of the configuration:
Observed behavior
labels:field at the update level is ignoredgroups.*levelThis only affects security update PRs.
Regular (non-security) Dependabot PRs do receive labels as expected.
Expected behavior
One of the following would be expected:
updatesentry, orWhy this matters
In larger organizations, labels are critical for:
Grouped security PRs without labels are hard to triage and break existing workflows.
Questions
Thanks in advance 🙏
Beta Was this translation helpful? Give feedback.
All reactions