Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Update docs about permissions required for managing dependabot-related secrets #40872

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
r7kamura wants to merge 1 commit into github:main
base: main
Choose a base branch
Loading
from r7kamura:secrets-permission

Conversation

@r7kamura
Copy link

@r7kamura r7kamura commented Oct 16, 2025
edited
Loading

Why:

Historically, it was already possible to manage secrets via the REST API with Write permissions, even though the GitHub web interface did not provide a UI for it at the time. Recently, the web UI has also been updated to allow secret management directly.
(As of October 16, 2025, it appears that the current UI has an issue where, if there are no Dependabot secrets yet, the link to the page for adding them is not displayed. However, it is still possible to access and manage Dependabot secrets by directly entering the page’s URL)

According to the following documentation, users with Write permission can now manage repository secrets:

This update to the documentation appears to have been made in the following pull request:

Based on these facts, the current explanation stating that Owner or Admin permissions are required is no longer accurate.
I’d like to propose updating the description to reflect the actual behavior — namely, that Write permissions are sufficient to manage Dependabot-related secrets.

I verified this behavior in an organization repository where I have Write permission.
I haven’t tested it in a personal repository, so there’s a chance my understanding might not be entirely accurate in that case.
Reviewers are likely more familiar with the details here, so I’d appreciate it if you could double-check whether write permission is also sufficient for personal repositories.

What's being changed (if available, include any code snippets, screenshots, or gifs):

I’ve updated the description, which previously stated that Owner or Admin permissions were required to create secrets, to now indicate that Write permission is sufficient.

Check off the following:

  • A subject matter expert (SME) has reviewed the technical accuracy of the content in this PR. In most cases, the author can be the SME. Open source contributions may require an SME review from GitHub staff.
  • The changes in this PR meet the docs fundamentals that are required for all content.
  • All CI checks are passing and the changes look good in the review environment.

@Copilot Copilot AI review requested due to automatic review settings October 16, 2025 00:08
Copy link

welcome bot commented Oct 16, 2025

Thanks for opening this pull request! A GitHub docs team member should be by to give feedback soon. In the meantime, please check out the contributing guidelines.

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates documentation to accurately reflect the current permissions required for managing Dependabot-related repository secrets. The change corrects outdated information that stated owner/admin permissions were required, updating it to reflect that write access is now sufficient for both personal and organization repositories.

  • Updates permission requirements from "owner" or "admin" to "write" access
  • Simplifies the language by consolidating personal and organization repository requirements
  • Aligns documentation with current GitHub functionality where write access allows secret management

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

Copy link
Contributor

github-actions bot commented Oct 16, 2025
edited
Loading

How to review these changes 👓

Thank you for your contribution. To review these changes, choose one of the following options:

A Hubber will need to deploy your changes internally to review.

Table of review links

Note: Please update the URL for your staging server or codespace.

The table shows the files in the content directory that were changed in this pull request. This helps you review your changes on a staging server. Changes to the data directory are not included in this table.

Source Review Production What Changed
code-security/dependabot/working-with-dependabot/configuring-access-to-private-registries-for-dependabot.md fpt
ghec
ghes@ 3.18 3.17 3.16 3.15 3.14
fpt
ghec
ghes@ 3.18 3.17 3.16 3.15 3.14
from reusable

Key: fpt: Free, Pro, Team; ghec: GitHub Enterprise Cloud; ghes: GitHub Enterprise Server

🤖 This comment is automatically generated.

@github-actions github-actions bot added the triage Do not begin working on this issue until triaged by the team label Oct 16, 2025
Copy link
Contributor

Sharra-writes commented Oct 16, 2025
edited
Loading

@r7kamura Thanks for opening a PR! I'm reasonably sure this change is correct, but I'll check with the Dependabot team to make sure!

Edit: Sorry, I didn't mean Dependabot. It's getting late here. I don't remember which team we were working with on this, but it's definitely on my project board somewhere.

r7kamura reacted with thumbs up emoji

@Sharra-writes Sharra-writes added content This issue or pull request belongs to the Docs Content team and removed triage Do not begin working on this issue until triaged by the team labels Oct 16, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

Copilot code review Copilot Copilot left review comments

At least 1 approving review is required to merge this pull request.

Assignees

No one assigned

Labels

content This issue or pull request belongs to the Docs Content team

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

AltStyle によって変換されたページ (->オリジナル) /