Dependabot - Private "Registries"/"Dependencies"/"Repositories" is misleading

Open Beginner friendly
#45,681 6 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
1/5
Estimated time
Under an hour
Newbie friendliness
82/100
Issue type
Documentation
Clarity
Mostly clear
Activity status
Active
Tech stack
github
Domain
documentation

Research direction

Read the affected article at docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories, focusing on the three uses of “Private Registries,” “Private Dependencies,” and “Private Repositories.” Harmonize the terminology so the scope of private dependencies and repositories is clear, then review the rendered article for consistent wording.

Written by the indexing model from the issue text.

Description

content dependabot needs SME
Code of Conduct
What article on docs.github.com is affected?

https://docs.github.com/en/code-security/reference/supply-chain-security/supported-ecosystems-and-repositories

What part(s) of the article would you like to see updated?

Dependabot sometimes cannot resolve private dependencies for some ecosystems (e.g. Nix, currently)

However, this is expressed in 3 different expressions:

  1. Private Registries
  2. Private Dependencies
  3. Private Repositories

Those can be misleading

For example:
I personally thought dependabot was completely not working for some ecosystems independently of private dependencies when the dependabot.yml file was inside of a private repository

Harmonizing the "Private *" term with a single word (probably "Private Dependencies", since it encompasses both registries and repositories) would have cleared up any confusion

Additional information

No response

Dominant language
TypeScript
Stars
20.9k
Forks
68.8k
Avg merge
15h 4m
Merged PRs (30d)
103

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/docs

All issues in github/docs

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.