Visitar URL original
Dependabot - Private "Registries"/"Dependencies"/"Repositories" is misleading · Issue #45681 · github/docs · GitHub
Skip to content

Dependabot - Private "Registries"/"Dependencies"/"Repositories" is misleading #45681

Description

@Malix-Labs

Code of Conduct

What article on docs.github.com is affected?

https://docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories

What part(s) of the article would you like to see updated?

Dependabot sometimes cannot resolve private dependencies for some ecosystems (e.g. Nix, currently)

However, this is expressed in 3 different expressions:

  1. Private Registries
  2. Private Dependencies
  3. Private Repositories

Those can be misleading

For example:
I personally thought dependabot was completely not working for some ecosystems independently of private dependencies when the dependabot.yml file was inside of a private repository

Harmonizing the "Private *" term with a single word (probably "Private Dependencies", since it encompasses both registries and repositories) would have cleared up any confusion

Additional information

No response

Activity

added
contentThis issue or pull request belongs to the Docs Content team
on Aug 31, 2026
changed the title [-]Dependabot - Private "Registries"/"Repositories"/"Dependencies" is misleading[/-] [+]Dependabot - Private "Registries"/"Dependencies"/"Repositories" is misleading[/+] on Aug 31, 2026
added
triageDo not begin working on this issue until triaged by the team
on Aug 31, 2026

subatoi commented on Sep 1, 2026

@subatoi
Contributor

@Malix-Labs Thanks for raising an issue—could I just clarify, are you providing feedback that the content is confusing, or that the feature is confusing and the documentation is incomplete? Many thanks

Malix-Labs commented on Sep 1, 2026

@Malix-Labs
ContributorAuthor

That the documentation content is confusing, indeed

subatoi commented on Sep 1, 2026

@subatoi
Contributor

OK, thank you—may I ask if there are specific changes you'd propose making, that would have made things clearer for you? Just so that I can make sure I can provide this feedback to the right people, and see if there's anything we can do.

Malix-Labs commented on Sep 1, 2026

@Malix-Labs
ContributorAuthor

I thought I wrote this part already but the edit must have probably not be saved!

Harmonizing the "Private *" term with a single word (probably "Private Dependencies", since it encompasses both registries and repositories) would have cleared up any confusion

subatoi commented on Sep 1, 2026

@subatoi
Contributor

No problem @Malix-Labs, thanks! I've edited your original description. I'll triage this for review with the relevant team.

added
needs SMEThis proposal needs review from a subject matter expert
and removed
triageDo not begin working on this issue until triaged by the team
on Sep 1, 2026

github-actions commented on Sep 1, 2026

@github-actions
Contributor

Thanks for opening an issue! We've triaged this issue for technical review by a subject matter expert 👀

deleted a comment from HyphensPeciwse33 on Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    contentThis issue or pull request belongs to the Docs Content teamdependabotContent related to Dependabotdriver personaneeds SMEThis proposal needs review from a subject matter expert

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions