marocchino / validate-dependabot

validate dependabot yaml

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

False negative: "Update configs must have a unique combination of 'package-ecosystem', 'directory', and 'target-branch'"

corneliusroemer opened this issue · comments

Dependabot validate lets this through:

version: 2
updates:
  - package-ecosystem: docker
    directory: website
    schedule:
      interval: weekly
    groups:
      minorAndPatch:
          update-types:
            - "minor"
            - "patch"
  - package-ecosystem: docker
    directories:
      - website
      - backend
    schedule:
      interval: weekly
    groups:
      minorAndPatch:
          update-types:
            - "minor"
            - "patch"

even though dependabot itself complains with:

Update configs must have a unique combination of 'package-ecosystem', 'directory', and 'target-branch'
Brave Browser 2024-05-11 17 20 10