The information is based on DevOps.com’s report: the story materials do not contain the full text of GitHub’s announcement.
GitHub moved Dependabot, a tool for updating dependencies, to authentication in its package registries through GITHUB_TOKEN, a token used by GitHub Actions jobs. Dependabot can now fetch dependencies there without a separate personal access token.
When fetching a dependency, Dependabot requests packages: Read access and sends GITHUB_TOKEN automatically. If a repository already has package access through Manage Actions access, Dependabot inherits it just as a GitHub Actions job does.
GitHub first released this capability in June, but rolled it back because of npm dependency-resolution problems. It is now generally available again, with token authentication as the default and personal access tokens retained as a fallback.
Claim check:
- Dependabot can authenticate to GitHub Packages, GitHub Container Registry, and other GitHub-hosted registries through GITHUB_TOKEN without a personal access token. (confirmed only by the carrying publication: evidence; «Dependabot can authenticate directly to GitHub Packages, the GitHub Container Registry ( ghcr.io ), and other GitHub-hosted package registries without a PAT. It uses the same GITHUB_TOKEN mechanism»)
- Dependabot opens pull requests for outdated or vulnerable dependencies. (confirmed only by the carrying publication: evidence; «It still opens pull requests for outdated or vulnerable dependencies»)
- When fetching a dependency, Dependabot requests packages: Read access and sends GITHUB_TOKEN automatically. (confirmed only by the carrying publication: evidence; «requesting packages: Read access and presenting that token automatically when it pulls a dependency»)
- If a repository has package access through Manage Actions access, Dependabot inherits that access as a GitHub Actions workflow does. (confirmed only by the carrying publication: evidence; «If a repository already has access to a package through the “Manage Actions access” setting, Dependabot inherits that access the same way an Actions workflow would.»)
- GitHub first released this capability in June and then rolled it back because of npm dependency-resolution problems. (confirmed only by the carrying publication: evidence; «GitHub first shipped this capability in June. It ran into trouble with npm dependency resolution and had to be rolled back»)
- The capability is generally available again, with token authentication as the default and personal access tokens retained as a fallback. (confirmed only by the carrying publication: evidence; «It’s back now, generally available, with token-based authentication as the default and PAT-based credentials preserved as a fallback rather than removed outright.»)
Publications:
score 70.5 · kind announcement · revision 1 · stories st-1s9pea4