Skip to content

Yarn's npmMinimalAgeGate option blocks Dependabot from making security updates #15137

@legowerewolf

Description

@legowerewolf

Is there an existing issue for this?

  • I have searched the existing issues

Package ecosystem

yarn

Package manager version

yarn 4.15.0

Language version

Should be irrelevant, but I noticed it with a Node 24 project.

Manifest location and content before the Dependabot update

No response

dependabot.yml content

No response

Updated dependency

No response

What you expected to see, versus what you actually saw

I expected Dependabot to make a security update PR to fix the advisory but instead it was showing an error that the fixed version was too recent for Yarn to allow it.

Native package manager behavior

yarn up @sveltejs/kit failed for the same quarantine reason.

yarn up --no-time-gate @sveltejs/kit works.

Images of the diff or a link to the PR, issue, or logs

No response

Smallest manifest that reproduces the issue

No response

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions