Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Add Dependabot permissions warnings #37733

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
Marcono1234 wants to merge 1 commit into github:main
base: main
Choose a base branch
Loading
from Marcono1234:dependabot-permissions-warning

Conversation

Copy link
Contributor

@Marcono1234 Marcono1234 commented Apr 23, 2025
edited
Loading

Why:

Dependabot intentionally has no built-in automerge feature (dependabot/dependabot-core#1973 (comment)), and in the past permissions for Dependabot workflows were changed to read-only by default (changelog entry).

If I understand it correctly, the concern is that a Dependabot workflow with write permissions could be exploited by a compromised dependency to immediately compromise the consuming repository as soon as the Dependabot PR is created, without any interaction of the owner.

Therefore adding a custom automerge workflow for Dependabot or giving its workflows write permissions can be a security risk, and is probably worth pointing out in the documentation.

Slightly related to #37657, but does not resolve it

What's being changed (if available, include any code snippets, screenshots, or gifs):

Add warnings to the documentation to inform users about the risk of giving Dependabot workflows more permissions.

I hope these warnings do not seem like fear mongering (any feedback regarding wording is welcome!). Maybe some users who set up auto merging of Dependabot PRs might not consider this a big issue (or an issue at all).

Check off the following:

  • A subject matter expert (SME) has reviewed the technical accuracy of the content in this PR. In most cases, the author can be the SME. Open source contributions may require an SME review from GitHub staff.
  • The changes in this PR meet the docs fundamentals that are required for all content.
  • All CI checks are passing and the changes look good in the review environment.

@github-actions github-actions bot added the triage Do not begin working on this issue until triaged by the team label Apr 23, 2025
Copy link
Contributor

How to review these changes 👓

Thank you for your contribution. To review these changes, choose one of the following options:

A Hubber will need to deploy your changes internally to review.

Table of review links

⚠️ Warning: Our review server is experiencing latency issues.

The table shows the files in the content directory that were changed in this pull request. This helps you review your changes on the review server. Changes to the data directory are not included in this table.

Source Review Production What Changed
code-security/dependabot/troubleshooting-dependabot/troubleshooting-dependabot-on-github-actions.md fpt
ghec
ghes@ 3.16 3.15 3.14 3.13 3.12
fpt
ghec
ghes@ 3.16 3.15 3.14 3.13 3.12
code-security/dependabot/working-with-dependabot/automating-dependabot-with-github-actions.md fpt
ghec
ghes@ 3.16 3.15 3.14 3.13 3.12
fpt
ghec
ghes@ 3.16 3.15 3.14 3.13 3.12

Key: fpt: Free, Pro, Team; ghec: GitHub Enterprise Cloud; ghes: GitHub Enterprise Server

🤖 This comment is automatically generated.

Copy link
Contributor Author

Please let me know if I am misunderstanding the security risk here, or if you would like the warnings to be changed.

This comment was marked as spam.

This comment was marked as spam.

Copy link
Contributor

Sharra-writes commented Apr 23, 2025
edited
Loading

@Marcono1234 Thanks for opening these! I'll get this triaged and look for an SME to review the specifics. We appreciate the time you're investing to improve the documentation. 💛

@Sharra-writes Sharra-writes added content This issue or pull request belongs to the Docs Content team dependabot Content related to Dependabot needs SME This proposal needs review from a subject matter expert and removed triage Do not begin working on this issue until triaged by the team labels Apr 23, 2025
Copy link
Contributor

Thanks for opening a pull request! We've triaged this issue for technical review by a subject matter expert 👀

Cryptogreatness

This comment was marked as spam.

This comment was marked as spam.

Copy link
Contributor

This is a gentle bump for the docs team that this PR is waiting for technical review.

@github-actions github-actions bot added the SME stale The request for an SME has staled label May 29, 2025
@Sharra-writes Sharra-writes removed the SME stale The request for an SME has staled label May 29, 2025
Copy link
Contributor

This is a gentle bump for the docs team that this PR is waiting for technical review.

@github-actions github-actions bot added the SME stale The request for an SME has staled label Jun 29, 2025
@Sharra-writes Sharra-writes removed the SME stale The request for an SME has staled label Jun 30, 2025
Copy link
Contributor

This is a gentle reminder for the docs team that this PR is waiting for technical review by a subject matter expert.

@github-actions github-actions bot added the Waiting on SME review The request for a technical review by a subject matter expert has stalled. label Jul 30, 2025
@Sharra-writes Sharra-writes removed the Waiting on SME review The request for a technical review by a subject matter expert has stalled. label Jul 30, 2025
Copy link
Contributor

github-actions bot commented Sep 2, 2025

A stale label has been added to this pull request because it has been open 30 days with no activity. If you think this pull request should remain open, please add a new comment.

@github-actions github-actions bot added the Inactive Will be closed automatically by a stall check if no activity is detected. label Sep 2, 2025
@Sharra-writes Sharra-writes added never-stale Do not close as stale and removed Inactive Will be closed automatically by a stall check if no activity is detected. labels Sep 2, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Reviewers
1 more reviewer

@Cryptogreatness Cryptogreatness Cryptogreatness left review comments

Reviewers whose approvals may not affect merge requirements

At least 1 approving review is required to merge this pull request.

Assignees
No one assigned
Labels
content This issue or pull request belongs to the Docs Content team dependabot Content related to Dependabot needs SME This proposal needs review from a subject matter expert never-stale Do not close as stale
Projects
None yet
Milestone
No milestone
Development

Successfully merging this pull request may close these issues.

AltStyle によって変換されたページ (->オリジナル) /