# Dependabot strange behavior for Julia standard library packages

**URL:** <https://discourse.julialang.org/t/dependabot-strange-behavior-for-julia-standard-library-packages/139851>\
**Category:** Package Management\
**Tags:** question, dependencies\
**Created:** [October 6, 2026, 7:57am UTC](https://discourse.julialang.org/t/dependabot-strange-behavior-for-julia-standard-library-packages/139851 "2026-10-06T07:57:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![juthohaegeman](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/juthohaegeman/32/8620_2.png) [@juthohaegeman](https://discourse.julialang.org/u/juthohaegeman)\
**Post date:** [October 6, 2026, 7:57am UTC](https://discourse.julialang.org/t/dependabot-strange-behavior-for-julia-standard-library-packages/139851/1 "2026-10-06T07:57:29Z")

</div>

Why is dependabot trying to add version numbers “\<0.0.1” to Julia standard library packages (e.g. LinearAlgebra, Printf, Logging, ), when I currently just have version number “1” in the Project.toml file? See e.g. [Bump the all-julia-packages group with 7 updates - Pull Request #175 - Jutho/KrylovKit.jl - GitHub](https://github.com/Jutho/KrylovKit.jl/pull/175/changes) .

---

<div class="post-metadata">

**Author:** ![BjarkeHautop](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/bjarkehautop/32/219291_2.png) [@BjarkeHautop](https://discourse.julialang.org/u/BjarkeHautop)\
**Post date:** [October 6, 2026, 8:24am UTC](https://discourse.julialang.org/t/dependabot-strange-behavior-for-julia-standard-library-packages/139851/2 "2026-10-06T08:24:20Z")

</div>

Setting the minimum Julia version to 1.10 would stop it from doing that. See [PSA: Compat requirements in the General registry are changing](https://discourse.julialang.org/t/psa-compat-requirements-in-the-general-registry-are-changing/104958) for more details on why it’s doing that for versions below 1.10.

---

<div class="post-metadata">

**Author:** ![Eben60](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/eben60/32/13475_2.png) [@Eben60](https://discourse.julialang.org/u/Eben60)\
**Post date:** [October 6, 2026, 8:48am UTC](https://discourse.julialang.org/t/dependabot-strange-behavior-for-julia-standard-library-packages/139851/3 "2026-10-06T08:48:19Z")

</div>

See also [PSA: GitHub Dependabot now supports Julia - #17 by Tamas\_Papp](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/17) and the following discussion. Is probably still a bug in your case.

---

<div class="post-metadata">

**Author:** ![BjarkeHautop](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/bjarkehautop/32/219291_2.png) [@BjarkeHautop](https://discourse.julialang.org/u/BjarkeHautop)\
**Post date:** [October 6, 2026, 8:50am UTC](https://discourse.julialang.org/t/dependabot-strange-behavior-for-julia-standard-library-packages/139851/4 "2026-10-06T08:50:52Z")

</div>

It’s not (as far as I understand it). There was a bug that it happened to Julia versions with compat 1.10 (or above), which have been fixed. OP’s package has compat Julia 1.6, so it’s expected OP gets the PRs.

---

<div class="post-metadata">

**Author:** ![ianshmean](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ianshmean/32/216042_2.png) [@ianshmean](https://discourse.julialang.org/u/ianshmean)\
**Post date:** [October 6, 2026, 1:29pm UTC](https://discourse.julialang.org/t/dependabot-strange-behavior-for-julia-standard-library-packages/139851/5 "2026-10-06T13:29:11Z")

</div>

Indeed.

Here’s a PR to dependabot to add a note to explain it, as it does look odd for those unfamiliar with the issue.

> <https://github.com/dependabot/dependabot-core/pull/16308>
>
> Claude:
> 
> \---
> 
> \### What are you trying to accomplish?
> 
> When a project's \`julia\` c…ompat entry admits releases before 1.10, Dependabot gives each stdlib compat entry a \`\<0.0.1\` bound (#16229). Nothing in the PR says why, so it reads as a bug (\[Discourse thread\](https://discourse.julialang.org/t/dependabot-strange-behavior-for-julia-standard-library-packages/139851)).
> 
> The PR now carries one note, only when an update adds that bound:
> 
> \> \[!NOTE\]
> \> \`LinearAlgebra\`, \`Printf\` are standard libraries. Before Julia 1.10, \`Pkg.test()\` gave standard libraries version 0.0.0, so while the \`julia\` compat entry admits those releases, a stdlib compat entry needs \`\<0.0.1\` for tests to resolve. Raising the \`julia\` compat entry to \`1.10\` or later removes the need for it. See the \[stdlib compat PSA\](https://discourse.julialang.org/t/psa-compat-requirements-in-the-general-registry-are-changing/104958).
> 
> Entries that already had the bound, and other stdlib widenings, get no note.
> 
> \### Anything you want to highlight for special attention from reviewers?
> 
> One change outside \`julia/\`: \`Notice.markdown\_mode\` mapped INFO to \`\[!INFO\]\`, which GitHub does not render as an alert. No ecosystem showed an INFO notice in a PR before; it now maps to \`\[!NOTE\]\`.
> 
> \### How will you know you've accomplished your goal?
> 
> New file updater specs cover a stdlib entry gaining the bound (one NOTE notice) and one that already had it (none). Locally \`julia/spec\` (349 examples), \`common/spec/dependabot/notice\_spec.rb\`, rubocop and \`srb tc\` (no errors under \`julia/\`) pass.
> 
> \### Checklist
> 
> \- \[x\] I have run the complete test suite to ensure all tests and linters pass.
> \- \[x\] I have thoroughly tested my code changes to ensure they work as expected, including adding additional tests for new functionality.
> \- \[x\] I have written clear and descriptive commit messages.
> \- \[x\] I have provided a detailed description of the changes in the pull request, including the problem it addresses, how it fixes the problem, and any relevant details about the implementation.
> \- \[x\] I have ensured that the code is well-documented and easy to understand.
