github / github/docs

Dependabot - Private "Registries"/"Dependencies"/"Repositories" is misleading

オープン 初心者向け
#45,681 コメント 6 件 リアクション 0 件 担当者 0 名 GitHub で見る
content dependabot needs SME
主要言語
TypeScript
スター
20.8k
フォーク
68.7k
平均マージ
12時間 24分
マージ済み PR(30日)
105

説明

### Code of Conduct

- [x] I have read and agree to the GitHub Docs project's [Code of Conduct](https://github.com/github/docs/blob/main/.github/CODE_OF_CONDUCT.md)

### What article on docs.github.com is affected?

https://docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories

### What part(s) of the article would you like to see updated?

Dependabot sometimes cannot resolve private dependencies for some ecosystems (e.g. Nix, currently)

However, this is expressed in 3 different expressions:
1. Private **Registries**
2. Private **Dependencies**
3. Private **Repositories**

Those can be misleading

For example:
I personally thought dependabot was completely not working for some ecosystems independently of private dependencies when the `dependabot.yml` file was inside of a private repository

Harmonizing the "Private *" term with a single word (probably "Private Dependencies", since it encompasses both registries and repositories) would have cleared up any confusion

### Additional information

_No response_

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Read the affected article at docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories, focusing on the three uses of “Private Registries,” “Private Dependencies,” and “Private Repositories.” Harmonize the terminology so the scope of private dependencies and repositories is clear, then review the rendered article for consistent wording.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
github
領域
documentation
issue の種類
ドキュメント
難易度
1/5
見積もり時間
1時間未満
活発さ
活発
明瞭さ
おおむね明確
初心者へのやさしさ
82/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。