Skip to content

Update dependabot.yml#1256

Merged
chrjohn merged 1 commit into
masterfrom
chrjohn-dependabot-mina
Jun 11, 2026
Merged

Update dependabot.yml#1256
chrjohn merged 1 commit into
masterfrom
chrjohn-dependabot-mina

Conversation

@chrjohn

@chrjohn chrjohn commented Jun 11, 2026

Copy link
Copy Markdown
Member

Also see #1216

Added ignore rule for specific dependency version in Maven updates.

Root Cause: In November 2022, https://github.com/dependabot ignore this minor version was used on #509, which blocked all mina-core 2.2.x updates. The repo's mina-core is currently at 2.2.4, and there's now a security advisory requiring a newer 2.2.x patch — but Dependabot's stored ignore rule is still blocking those versions. Since the PR is >2 years old, https://github.com/dependabot unignore on it doesn't work.

Solution: GitHub's docs state that ignore conditions in dependabot.yml completely override any stored PR-comment-based ignores for that dependency.
Once the security PR is created and merged, you can remove this ignore entry entirely.

@chrjohn chrjohn added this to the QFJ 3.0.2 milestone Jun 11, 2026
@chrjohn chrjohn merged commit e50b4b6 into master Jun 11, 2026
21 checks passed
@chrjohn chrjohn deleted the chrjohn-dependabot-mina branch June 11, 2026 14:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant