github / github/docs

Dependabot - Private "Registries"/"Dependencies"/"Repositories" is misleading

未关闭 适合新手
#45,681 6 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
content dependabot needs SME
主要语言
TypeScript
星标
20.8k
派生
68.7k
平均合并
12 小时 24 分钟
30 天内合并 PR
105

描述

### Code of Conduct

- [x] I have read and agree to the GitHub Docs project's [Code of Conduct](https://github.com/github/docs/blob/main/.github/CODE_OF_CONDUCT.md)

### What article on docs.github.com is affected?

https://docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories

### What part(s) of the article would you like to see updated?

Dependabot sometimes cannot resolve private dependencies for some ecosystems (e.g. Nix, currently)

However, this is expressed in 3 different expressions:
1. Private **Registries**
2. Private **Dependencies**
3. Private **Repositories**

Those can be misleading

For example:
I personally thought dependabot was completely not working for some ecosystems independently of private dependencies when the `dependabot.yml` file was inside of a private repository

Harmonizing the "Private *" term with a single word (probably "Private Dependencies", since it encompasses both registries and repositories) would have cleared up any confusion

### Additional information

_No response_

贡献指南

打开贡献指南

调研方向

Read the affected article at docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories, focusing on the three uses of “Private Registries,” “Private Dependencies,” and “Private Repositories.” Harmonize the terminology so the scope of private dependencies and repositories is clear, then review the rendered article for consistent wording.

由索引模型根据 Issue 内容生成。

评估

技术栈
github
领域
documentation
Issue 类型
文档
难度
1/5
预计耗时
1 小时以内
活跃度
活跃
描述清晰度
基本清楚
新手友好度
82/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。