An issue we see every so often (most recently with #39327) is that folks using a package manager with a lockfile will be surprised that they do not receive updates for their PRs as part of "normal" Renovate usage.
Because - as far as I'm aware? - Renovate will not process packages that are managed through a lockfile and are unpinned.
(if i.e. fastapi==0.116.1 is used in the pyproject.toml, Renovate will suggest a bump, but not if fastapi is used)
One way to surface this would be to add a DEBUG log message that detects if any package files have a lockFiles entry
- Would there be any drawbacks from this?
- Should we also surface this with onboarding PRs (to note that "you will not receive PRs, unless you enable ..."?
- What additional documentation should we add, if we've got a gap?
Via #39429