Dependabot - Private "Registries"/"Dependencies"/"Repositories" is misleading
- Ngôn ngữ chính
- TypeScript
- Star
- 20.8k
- Fork
- 68.7k
- Merge trung bình
- 12 giờ 24 phút
- Pull request đã merge (30 ngày)
- 105
Mô tả
### Code of Conduct
- [x] I have read and agree to the GitHub Docs project's [Code of Conduct](https://github.com/github/docs/blob/main/.github/CODE_OF_CONDUCT.md)
### What article on docs.github.com is affected?
https://docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories
### What part(s) of the article would you like to see updated?
Dependabot sometimes cannot resolve private dependencies for some ecosystems (e.g. Nix, currently)
However, this is expressed in 3 different expressions:
1. Private **Registries**
2. Private **Dependencies**
3. Private **Repositories**
Those can be misleading
For example:
I personally thought dependabot was completely not working for some ecosystems independently of private dependencies when the `dependabot.yml` file was inside of a private repository
Harmonizing the "Private *" term with a single word (probably "Private Dependencies", since it encompasses both registries and repositories) would have cleared up any confusion
### Additional information
_No response_
Hướng dẫn đóng góp
Hướng nghiên cứu
Read the affected article at docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories, focusing on the three uses of “Private Registries,” “Private Dependencies,” and “Private Repositories.” Harmonize the terminology so the scope of private dependencies and repositories is clear, then review the rendered article for consistent wording.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- github
- Lĩnh vực
- documentation
- Loại issue
- Tài liệu
- Độ khó
- 1/5
- Thời gian dự kiến
- Dưới một giờ
- Mức độ hoạt động
- Sôi nổi
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 82/100