Dependabot GITHUB_TOKEN
permissions & secret access is contradicting / incomplete
#37657
Open
1 task done
Labels
content
This issue or pull request belongs to the Docs Content team
dependabot
Content related to Dependabot
needs SME
This proposal needs review from a subject matter expert
Code of Conduct
What article on docs.github.com is affected?
There are multiple parts of the documentation which say that Dependabot workflow runs act as if they are from a forked repository and therefore have limited privileges.
However, the documentation seems to be incomplete / contradicting:
docs/data/reusables/developer-site/pull_request_forked_repos_link.md
Lines 17 to 18 in e2f952a
linking to the relevant documentation)
docs/data/reusables/dependabot/dependabot-on-actions-troubleshooting-workflows.md
Line 9 in e2f952a
(it is actually explained further down in the same document, but maybe it would be useful to directly link there?)
docs/content/admin/managing-github-actions-for-your-enterprise/advanced-configuration-and-troubleshooting/troubleshooting-github-actions-for-your-enterprise.md
Line 71 in e2f952a
(is this really needed or does the github.com approach work for enterprises as well and should be preferred because it is safer?)
The only sections which actually provide detailed information seem to be:
https://github.com/github/docs/blame/e2f952a115fc4cb3d34281b1fa472ac3cd33e7da/content/code-security/dependabot/troubleshooting-dependabot/troubleshooting-dependabot-on-github-actions.md#L45
permissions
https://github.com/github/docs/blame/e2f952a115fc4cb3d34281b1fa472ac3cd33e7da/content/code-security/dependabot/troubleshooting-dependabot/troubleshooting-dependabot-on-github-actions.md#L81
What part(s) of the article would you like to see updated?
Additional information
No response
The text was updated successfully, but these errors were encountered: