Skip to content

Commit 4566302

Browse files
asciimikesaritai
andauthored
Update content/code-security/supply-chain-security/upgrading-from-dependabotcom-to-github-native-dependabot.md
Co-authored-by: Sarita Iyer <66540150+saritai@users.noreply.github.com>
1 parent 5520a9c commit 4566302

1 file changed

Lines changed: 1 addition & 2 deletions

File tree

content/code-security/supply-chain-security/upgrading-from-dependabotcom-to-github-native-dependabot.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -38,9 +38,8 @@ For more information about version updates with {% data variables.product.prodna
3838

3939
Upgrading from Dependabot Preview to {% data variables.product.prodname_dotcom %}-native {% data variables.product.prodname_dependabot %} requires you to merge the *Upgrade to GitHub-native Dependabot* pull request in your repository. This pull request includes the updated configuration file needed for {% data variables.product.prodname_dotcom %}-native {% data variables.product.prodname_dependabot %}.
4040

41-
If you are using private repositories, you will have to grant Dependabot access to these repositories in your organization's "Settings" > "Security & analysis" > "Grant Dependabot access to private repositories." Previously, Dependabot had access to all repositories within an organization, but this change was implemented as it is much safer by default, since Dependabot has least privilege.
41+
If you are using private repositories, you will have to grant Dependabot access to these repositories in your organization's security and analysis settings. For more information, see "[Allowing Dependabot to access private dependencies](https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization#allowing-dependabot-to-access-private-dependencies)". Previously, Dependabot had access to all repositories within an organization, but we implemented this change because it is much safer to use the principle of least privilege for Dependabot.
4242

4343
If you are using private registries, you will have to add your existing Dependabot Preview secrets to your repository's or organization's *Dependabot secrets*.
4444

4545
If you have any questions or need help migrating, you can view or open issues in the [dependabot/dependabot-core](https://github.com/dependabot/dependabot-core/issues) repository.
46-

0 commit comments

Comments
 (0)