Previously, if you specified your private registry configuration in the dependabot.yml
file and also had a configuration block for that ecosystem using the target-branch
key, Dependabot security updates wouldn’t utilize the private registry information as expected. Starting today, Dependabot now uses private registry configurations specified in the dependabot.yml
file as expected, even if there is a configuration with target-branch
. This ensures that security updates are applied correctly, regardless of your repository’s configuration settings. Note that security updates still does not support target-branch
configuration.
Learn more about configuring private registries for Dependabot in the Dependabot documentation.