Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot Alerts default permissions: write and maintain roles #609

Closed
github-product-roadmap opened this issue Nov 16, 2022 · 2 comments
Closed
Labels
cloud Available on Cloud dependabot Feature: GitHub Dependabot ga Feature phase: Generally available GitHub Advanced Security (GHAS) Product SKU: GitHub Advanced Security shipped Shipped

Comments

@github-product-roadmap
Copy link
Collaborator

github-product-roadmap commented Nov 16, 2022

Summary

Today by default, only those with the admin role for a repository can view or modify Dependabot alerts. With this change, anyone with write or maintain roles will also have permissions to view and modify Dependabot alerts by default.

Intended Outcome

Starting February 2023, default permissions for Dependabot alerts are changing so that the right collaborators can see and action on Dependabot alerts.

How will it work?

  • Based on your repository permissions, if you have write or maintain access, you'll be able to view and action on Dependabot alerts.

  • Based on your user notification settings and per-repository watching settings, you'll begin receiving notifications on Dependabot alerts.

You can adjust your user notifications settings and per-repository watching settings to make sure you're receiving notifications on Dependabot alerts for the repositories you care about.

@github github locked and limited conversation to collaborators Nov 16, 2022
@github-product-roadmap github-product-roadmap added cloud Available on Cloud ga Feature phase: Generally available GitHub Advanced Security (GHAS) Product SKU: GitHub Advanced Security security & compliance labels Nov 16, 2022
@ankneis ankneis moved this to Q1 2023 – Jan-Mar in GitHub Public Roadmap Nov 16, 2022
@ankneis ankneis added the dependabot Feature: GitHub Dependabot label Dec 21, 2022
@ankneis ankneis added the shipped Shipped label Feb 7, 2023
@ankneis
Copy link
Collaborator

ankneis commented Feb 7, 2023

🚢 This has shipped to dotcom: https://github.blog/changelog/2023-02-07-dependabot-alerts-default-permissions-change.

Leaving open to track GHES release!

@ankneis
Copy link
Collaborator

ankneis commented Jul 6, 2023

🚢 This has shipped with GHES 3.9: https://docs.github.com/en/[email protected]/admin/release-notes. Closing as complete.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
cloud Available on Cloud dependabot Feature: GitHub Dependabot ga Feature phase: Generally available GitHub Advanced Security (GHAS) Product SKU: GitHub Advanced Security shipped Shipped
Projects
Archived in project
Development

No branches or pull requests

2 participants