Skip to content

Commit 313d08d

Browse files
committed
Merge branch 'mm-dependabot-date' of github.com:github/docs-internal into mm-dependabot-date
2 parents 7475f95 + 7a8e268 commit 313d08d

1 file changed

Lines changed: 2 additions & 3 deletions

File tree

content/code-security/supply-chain-security/upgrading-from-dependabotcom-to-github-native-dependabot.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -40,9 +40,8 @@ For more information about version updates with {% data variables.product.prodna
4040

4141
Upgrading from Dependabot Preview to {% data variables.product.prodname_dotcom %}-native {% data variables.product.prodname_dependabot %} requires you to merge the *Upgrade to GitHub-native Dependabot* pull request in your repository. This pull request includes the updated configuration file needed for {% data variables.product.prodname_dotcom %}-native {% data variables.product.prodname_dependabot %}.
4242

43-
If you are using private repositories, you will have to grant Dependabot access to these repositories in your organization's "Settings" > "Security & analysis" > "Grant Dependabot access to private repositories." Previously, Dependabot had access to all repositories within an organization, but this change was implemented as it is much safer by default, since Dependabot has least privilege.
43+
If you are using private repositories, you will have to grant Dependabot access to these repositories in your organization's security and analysis settings. For more information, see "[Allowing Dependabot to access private dependencies](https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization#allowing-dependabot-to-access-private-dependencies)". Previously, Dependabot had access to all repositories within an organization, but we implemented this change because it is much safer to use the principle of least privilege for Dependabot.
4444

45-
If you are using private registries, you will have to add your existing Dependabot Preview secrets to your repository's or organization's *Dependabot secrets*.
45+
If you are using private registries, you will have to add your existing Dependabot Preview secrets to your repository's or organization's "Dependabot secrets". For more information, see "[Managing encrypted secrets for Dependabot](https://docs.github.com/en/code-security/supply-chain-security/managing-encrypted-secrets-for-dependabot)".
4646

4747
If you have any questions or need help migrating, you can view or open issues in the [dependabot/dependabot-core](https://github.com/dependabot/dependabot-core/issues) repository.
48-

0 commit comments

Comments
 (0)