Post #4021528
2026-07-22 23:02 UTC
Can anyone explain why I'm getting Dependabot security updates a branch of a repo that *isn't* the default branch for the repo?
The branch *was* the default branch 6 months ago - but I've changed the default branch, *and* I've renamed the requirements file in the "old default" branch... and yet, I'm still getting security notifications for packages in that requirements file.
(Repo in question is https://github.com/beeware/beeware.github.io; the `lektor` branch is the "old default". I just got a notification that "mistune" has a security issue; dependabot says the last commit it scanned was 6e496e3, which is on the main branch).
Replies (0)
No replies.