-
Notifications
You must be signed in to change notification settings - Fork 63.9k
Update configuring-dependabot-security-updates.md #16881
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
Thanks for opening this pull request! A GitHub docs team member should be by to give feedback soon. In the meantime, please check out the contributing guidelines. |
Automatically generated comment ℹ️This comment is automatically generated and will be overwritten every time changes are committed to this branch. The table contains an overview of files in the Content directory changesYou may find it useful to copy this table into the pull request summary. There you can edit it to share links to important articles or changes and to give a high-level overview of how the changes in your pull request support the overall goals of the pull request.
|
|
@raineorshine |
|
I'll review this tomorrow! |
|
@raineorshine 👋🏻 - thanks for contributing to our docs ✨
Could you let me know if you're referring to Dependabot version updates or Dependabot security updates? Or if you're not sure. That'll enable me to help you with this PR. Thank you so much 🙏🏻 🙂 |
|
Ah, okay. I'm talking about dependabot version updates. I didn't recognize there were distinct types of updates. I've been trying for months to disable them, and I kept getting directed to dependabot security update instructions when I searched. Maybe we should link the docs? As in, "Are you looking for dependabot version updates? See: X" |
|
I'm so sorry to hear that the docs are confusing in this respect 😢 |
|
@raineorshine 👋🏻 - thank you again for bringing this to our attention 💖 |
|
Great, thanks for your follow through. |
Why:
Dependabot continues giving updates even after being disabled if a
dependabot.ymlfile is present. Deletingdependabot.ymlis a necessary step for disabling dependabot completely.This was perplexing me for months, but I found the solution here: https://github.community/t/disable-dependabot/143425/5
What's being changed:
A missing step is being added to the instructions for disabling dependabot.
Check off the following:
Writer impact (This section is for GitHub staff members only):