Repository navigation
Dependabot - Private "Registries"/"Dependencies"/"Repositories" is misleading #45681
Description
Activity
@Malix-Labs Thanks for raising an issue—could I just clarify, are you providing feedback that the content is confusing, or that the feature is confusing and the documentation is incomplete? Many thanks
That the documentation content is confusing, indeed
OK, thank you—may I ask if there are specific changes you'd propose making, that would have made things clearer for you? Just so that I can make sure I can provide this feedback to the right people, and see if there's anything we can do.
I thought I wrote this part already but the edit must have probably not be saved!
Harmonizing the "Private *" term with a single word (probably "Private Dependencies", since it encompasses both registries and repositories) would have cleared up any confusion
No problem @Malix-Labs, thanks! I've edited your original description. I'll triage this for review with the relevant team.
Thanks for opening an issue! We've triaged this issue for technical review by a subject matter expert 👀
Code of Conduct
What article on docs.github.com is affected?
https://docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories
What part(s) of the article would you like to see updated?
Dependabot sometimes cannot resolve private dependencies for some ecosystems (e.g. Nix, currently)
However, this is expressed in 3 different expressions:
Those can be misleading
For example:
I personally thought dependabot was completely not working for some ecosystems independently of private dependencies when the
dependabot.ymlfile was inside of a private repositoryHarmonizing the "Private *" term with a single word (probably "Private Dependencies", since it encompasses both registries and repositories) would have cleared up any confusion
Additional information
No response