Dependabot - Private "Registries"/"Dependencies"/"Repositories" is misleading
- 主要語言
- TypeScript
- 星號
- 20.8k
- 分支
- 68.7k
- 平均合併
- 13 小時 10 分鐘
- 30 天內合併 PR
- 111
描述
### Code of Conduct
- [x] I have read and agree to the GitHub Docs project's [Code of Conduct](https://github.com/github/docs/blob/main/.github/CODE_OF_CONDUCT.md)
### What article on docs.github.com is affected?
https://docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories
### What part(s) of the article would you like to see updated?
Dependabot sometimes cannot resolve private dependencies for some ecosystems (e.g. Nix, currently)
However, this is expressed in 3 different expressions:
1. Private **Registries**
2. Private **Dependencies**
3. Private **Repositories**
Those can be misleading
For example:
I personally thought dependabot was completely not working for some ecosystems independently of private dependencies when the `dependabot.yml` file was inside of a private repository
Harmonizing the "Private *" term with a single word (probably "Private Dependencies", since it encompasses both registries and repositories) would have cleared up any confusion
### Additional information
_No response_
貢獻指南
研究方向
閱讀 docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories 中受影響的文章,著重查看「Private Registries」、「Private Dependencies」和「Private Repositories」這三處用法。統一術語,明確私有相依項目和私有儲存庫的範圍,然後檢查轉譯後的文章,確保措辭一致。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- github
- 領域
- documentation
- Issue 類型
- 文件
- 難度
- 1/5
- 預估耗時
- 1 小時以內
- 活躍度
- 活躍
- 描述清晰度
- 基本清楚
- 新手友好度
- 82/100