github / github/docs

Dependabot - Private "Registries"/"Dependencies"/"Repositories" is misleading

Offen Anfängerfreundlich
#45,681 6 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
content dependabot needs SME
Vorherrschende Sprache
TypeScript
Sterne
20.8k
Forks
68.7k
Ø Merge
12 Std. 24 Min.
Gemergte PRs (30 T.)
105

Beschreibung

### Code of Conduct

- [x] I have read and agree to the GitHub Docs project's [Code of Conduct](https://github.com/github/docs/blob/main/.github/CODE_OF_CONDUCT.md)

### What article on docs.github.com is affected?

https://docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories

### What part(s) of the article would you like to see updated?

Dependabot sometimes cannot resolve private dependencies for some ecosystems (e.g. Nix, currently)

However, this is expressed in 3 different expressions:
1. Private **Registries**
2. Private **Dependencies**
3. Private **Repositories**

Those can be misleading

For example:
I personally thought dependabot was completely not working for some ecosystems independently of private dependencies when the `dependabot.yml` file was inside of a private repository

Harmonizing the "Private *" term with a single word (probably "Private Dependencies", since it encompasses both registries and repositories) would have cleared up any confusion

### Additional information

_No response_

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Read the affected article at docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories, focusing on the three uses of “Private Registries,” “Private Dependencies,” and “Private Repositories.” Harmonize the terminology so the scope of private dependencies and repositories is clear, then review the rendered article for consistent wording.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
github
Bereich
documentation
Issue-Typ
Dokumentation
Schwierigkeit
1/5
Geschätzter Aufwand
Unter einer Stunde
Aktivitätsstatus
Aktiv
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
82/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.