Skip to content

Dependabot GITHUB_TOKEN permissions & secret access is contradicting / incomplete #37657

Open
@Marcono1234

Description

@Marcono1234

Code of Conduct

What article on docs.github.com is affected?

There are multiple parts of the documentation which say that Dependabot workflow runs act as if they are from a forked repository and therefore have limited privileges.

However, the documentation seems to be incomplete / contradicting:

The only sections which actually provide detailed information seem to be:

What part(s) of the article would you like to see updated?

  • If possible please consolidate the information
  • Remove contradictions
  • Add links so that the sections not only say "you can increase permissions, you can access secrets", but also link to the relevant sections about how to do it
  • Document the security concerns / the rationale why the token has read-only permissions by default and why there are dedicated Dependabot secrets, so that users are hopefully careful with changing this

Additional information

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    contentThis issue or pull request belongs to the Docs Content teamdependabotContent related to Dependabotneeds SMEThis proposal needs review from a subject matter expert

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions