Dependabot Alerts default permissions: write
and maintain
roles
#609
Labels
cloud
Available on Cloud
dependabot
Feature: GitHub Dependabot
ga
Feature phase: Generally available
GitHub Advanced Security (GHAS)
Product SKU: GitHub Advanced Security
shipped
Shipped
Summary
Today by default, only those with the
admin
role for a repository can view or modify Dependabot alerts. With this change, anyone withwrite
ormaintain
roles will also have permissions to view and modify Dependabot alerts by default.Intended Outcome
Starting February 2023, default permissions for Dependabot alerts are changing so that the right collaborators can see and action on Dependabot alerts.
How will it work?
Based on your repository permissions, if you have
write
ormaintain
access, you'll be able to view and action on Dependabot alerts.Based on your user notification settings and per-repository watching settings, you'll begin receiving notifications on Dependabot alerts.
You can adjust your user notifications settings and per-repository watching settings to make sure you're receiving notifications on Dependabot alerts for the repositories you care about.
The text was updated successfully, but these errors were encountered: