Skip to content

Dependabot GITHUB_TOKEN permissions & secret access is contradicting / incomplete #37657

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
1 task done
Marcono1234 opened this issue Apr 20, 2025 · 3 comments
Open
1 task done
Labels
content This issue or pull request belongs to the Docs Content team dependabot Content related to Dependabot needs SME This proposal needs review from a subject matter expert

Comments

@Marcono1234
Copy link
Contributor

Marcono1234 commented Apr 20, 2025

Code of Conduct

What article on docs.github.com is affected?

There are multiple parts of the documentation which say that Dependabot workflow runs act as if they are from a forked repository and therefore have limited privileges.

However, the documentation seems to be incomplete / contradicting:

The only sections which actually provide detailed information seem to be:

What part(s) of the article would you like to see updated?

  • If possible please consolidate the information
  • Remove contradictions
  • Add links so that the sections not only say "you can increase permissions, you can access secrets", but also link to the relevant sections about how to do it
  • Document the security concerns / the rationale why the token has read-only permissions by default and why there are dedicated Dependabot secrets, so that users are hopefully careful with changing this

Additional information

No response

@Marcono1234 Marcono1234 added the content This issue or pull request belongs to the Docs Content team label Apr 20, 2025
@github-actions github-actions bot added the triage Do not begin working on this issue until triaged by the team label Apr 20, 2025
@Sharra-writes
Copy link
Contributor

Thanks so much for opening an issue! I'll get this triaged for review.

@Sharra-writes Sharra-writes added dependabot Content related to Dependabot needs SME This proposal needs review from a subject matter expert and removed triage Do not begin working on this issue until triaged by the team labels Apr 21, 2025
Copy link
Contributor

Thanks for opening an issue! We've triaged this issue for technical review by a subject matter expert 👀

@Sharra-writes
Copy link
Contributor

@Marcono1234 Hi! I've have some SMEs who have been looking through your issues/PRs and I do need to follow up with them to see if they have anything to tell me, but this PR was just opened and merged today, and I don't know if it's related to/addresses any of your concerns. If you would be willing to take a look and let me know, that would be amazing. If not, that's fine, I'll ask around. It's just crazy with Build right now, and I don't know if anyone has the bandwidth to answer my questions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
content This issue or pull request belongs to the Docs Content team dependabot Content related to Dependabot needs SME This proposal needs review from a subject matter expert
Projects
None yet
Development

No branches or pull requests

2 participants