Skip to content

Can I limit dependabot to only open PRs when items in requirements txt have related CVE? #127267

Discussion options

You must be logged in to vote

It seems that the issue is the unconventional name for the requirements file.

Renaming it to requirements.txt allowed the behavior I was looking for (after disabling the scanning), I guess it's just an oddity that the version scanning did NOT needs the file named requirements.txt

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by YesThatAllen
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Code Security Build security into your GitHub workflow with features to keep your codebase secure Question
1 participant