vulnerabilityAlerts PRs not created
#46581
How are you running Renovate?A Mend.io-hosted app Which platform you running Renovate on?Other (please specify) Which version of Renovate are you using?Self-hosted github app (42.99.0) Please tell us more about your question or problemVulnerabilities are picked up from github security, they show up in the log, but it does not produce the security PRs Logs (if relevant)LogsFull log: https://github.com/teemtee/tmt/actions/runs/36691379243 |
Answered by
RahulGautamSingh
Sep 30, 2026
Replies: 1 comment 6 replies
|
Transitive dependencies are not remediated individually. Renovate does pick up both alerts (you can see the Renovate only creates vulnerability PRs for dependencies it extracts from the package file, so the alert rules have nothing to match, and no PR is created. |
6 replies
Answer selected by
RahulGautamSingh
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Transitive dependencies are not remediated individually.
Renovate does pick up both alerts (you can see the
alertPackageRulesin your log), butsetuptoolsandoauthlibare not declared in yourpyproject.toml. They only exist inuv.lockas transitive dependencies (oauthlibviarequests-oauthlib,setuptoolsvia copr, mrack and pbr).Renovate only creates vulnerability PRs for dependencies it extracts from the package file, so the alert rules have nothing to match, and no PR is created.