diff --git a/content/code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph.md b/content/code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph.md index c5214ea0dd87..9fd3cb232e85 100644 --- a/content/code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph.md +++ b/content/code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph.md @@ -86,7 +86,7 @@ The recommended formats explicitly define which versions are used for all direct {%- ifversion github-actions-in-dependency-graph %} | {% data variables.product.prodname_actions %} workflows [1] | YAML | `.yml`, `.yaml` | `.yml`, `.yaml` | {%- endif %} -| Go modules | Go | `go.sum` | `go.mod`, `go.sum` | +| Go modules | Go | `go.mod`| `go.mod`{% ifversion ghes < 3.9 or ghae < 3.9 %}, `go.sum`{% endif %} | | Maven | Java, Scala | `pom.xml` | `pom.xml` | | npm | JavaScript | `package-lock.json` | `package-lock.json`, `package.json`| | pip | Python | `requirements.txt`, `pipfile.lock` | `requirements.txt`, `pipfile`, `pipfile.lock`, `setup.py`[2] | diff --git a/data/reusables/dependabot/dependabot-alerts-dependency-scope.md b/data/reusables/dependabot/dependabot-alerts-dependency-scope.md index 4983fce6dae9..8da582f415f8 100644 --- a/data/reusables/dependabot/dependabot-alerts-dependency-scope.md +++ b/data/reusables/dependabot/dependabot-alerts-dependency-scope.md @@ -4,8 +4,8 @@ The table below summarizes whether dependency scope is supported for various eco |:---|:---:|:---:|:---|{% ifversion dependency-graph-dart-support %} | Dart | pub | pubspec.yaml | ✔ | | Dart | pub | pubspec.lock | ✔ |{% endif %} -| Go | Go modules | go.mod | No, defaults to runtime | -| Go | Go modules | go.sum | No, defaults to runtime | +| Go | Go modules | go.mod | No, defaults to runtime |{% ifversion ghes < 3.9 or ghae < 3.9 %} +| Go | Go modules | go.sum | No, defaults to runtime |{% endif %} | Java | Maven | pom.xml | ✔ `test` maps to development, else scope defaults to runtime | | JavaScript | npm | package.json | ✔ | | JavaScript | npm | package-lock.json | ✔ |