Skip to content

Dependabot GITHUB_TOKEN permissions & secret access is contradicting / incomplete #37657

@Marcono1234

Description

@Marcono1234

Code of Conduct

What article on docs.github.com is affected?

There are multiple parts of the documentation which say that Dependabot workflow runs act as if they are from a forked repository and therefore have limited privileges.

However, the documentation seems to be incomplete / contradicting:

The only sections which actually provide detailed information seem to be:

What part(s) of the article would you like to see updated?

  • If possible please consolidate the information
  • Remove contradictions
  • Add links so that the sections not only say "you can increase permissions, you can access secrets", but also link to the relevant sections about how to do it
  • Document the security concerns / the rationale why the token has read-only permissions by default and why there are dedicated Dependabot secrets, so that users are hopefully careful with changing this

Additional information

No response

Metadata

Metadata

Assignees

Labels

contentThis issue or pull request belongs to the Docs Content teamdependabotContent related to Dependabotneeds SMEThis proposal needs review from a subject matter expert

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions