github / github/docs

Dependabot - Private "Registries"/"Dependencies"/"Repositories" is misleading

未關閉 適合新手
#45,681 6 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
content dependabot needs SME
主要語言
TypeScript
星號
20.8k
分支
68.7k
平均合併
13 小時 10 分鐘
30 天內合併 PR
111

描述

### Code of Conduct

- [x] I have read and agree to the GitHub Docs project's [Code of Conduct](https://github.com/github/docs/blob/main/.github/CODE_OF_CONDUCT.md)

### What article on docs.github.com is affected?

https://docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories

### What part(s) of the article would you like to see updated?

Dependabot sometimes cannot resolve private dependencies for some ecosystems (e.g. Nix, currently)

However, this is expressed in 3 different expressions:
1. Private **Registries**
2. Private **Dependencies**
3. Private **Repositories**

Those can be misleading

For example:
I personally thought dependabot was completely not working for some ecosystems independently of private dependencies when the `dependabot.yml` file was inside of a private repository

Harmonizing the "Private *" term with a single word (probably "Private Dependencies", since it encompasses both registries and repositories) would have cleared up any confusion

### Additional information

_No response_

貢獻指南

開啟貢獻指南

研究方向

閱讀 docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories 中受影響的文章,著重查看「Private Registries」、「Private Dependencies」和「Private Repositories」這三處用法。統一術語,明確私有相依項目和私有儲存庫的範圍,然後檢查轉譯後的文章,確保措辭一致。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
github
領域
documentation
Issue 類型
文件
難度
1/5
預估耗時
1 小時以內
活躍度
活躍
描述清晰度
基本清楚
新手友好度
82/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。