Renovate updates gradle substitutions #39858
Unanswered
twam
asked this question in
Request Help
Replies: 1 comment 3 replies
-
|
At the moment, the gradle parser in renovate doesn't handle To workaround this limitation you could either:
|
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
How are you running Renovate?
Self-hosted Renovate
Which platform you running Renovate on?
GitHub Enterprise Server
Which version of Renovate are you using?
41.173.1
Please tell us more about your question or problem
In our
build.gradle.ktsfiles we 'fix' CVEs but substituting vulnerable versions we indirectly depend on using something likeThis works until the next Renovate run which auto-updates (we allow patch updates to be auto-merged) to
I didn't find anyway to exclude the first of the versions to be updated. I don't want to exclude the lib (or that version) entirely as it's still fine to updated it elsewhere or the second version to a newer one.
Beta Was this translation helpful? Give feedback.
All reactions