Update Dependabot alerts notification settings details - #41791
Update Dependabot alerts notification settings details#41791mlkaufman14 wants to merge 1 commit into
Conversation
How to review these changes 👓Thank you for your contribution. To review these changes, choose one of the following options: A Hubber will need to deploy your changes internally to review. Table of review linksNote: Please update the URL for your staging server or codespace. The table shows the files in the
Key: fpt: Free, Pro, Team; ghec: GitHub Enterprise Cloud; ghes: GitHub Enterprise Server 🤖 This comment is automatically generated. |
|
@mlkaufman14 I don't see any documentation that's in our actual docs (from GitHub, not Microsoft) saying that notifications aren't enabled in public repositories by default, so I'm going to have to make sure it's expected behavior and not a bug. If there were conflicts in GitHub's documentation, I would just accept it, but if the GitHub documentation is consistent and the Microsoft documentation isn't, Microsoft may be observing what's happening in some cases rather than describing what should be happening. |
|
A stale label has been added to this pull request because it has been open 30 days with no activity. If you think this pull request should remain open, please add a new comment. |
|
A stale label has been added to this pull request because it has been open 30 days with no activity. If you think this pull request should remain open, please add a new comment. |
|
@mlkaufman14 Hello, and please accept my apologies for the late conclusion here This documentation has been extensively revamped since you originally raised this, and I believe the passages causing the confusion have been edited to be more explicit. If not, please feel free to add a new comment or raise a new issue or PR, but for now I'll go ahead and close this out. Thank you very much for your interest in the GitHub docs 🙇 |
Copied text from this documentation: https://learn.microsoft.com/en-us/training/modules/configure-dependabot-security-updates-on-github-repo/3-dependabot-alerts
Why:
There is mixed information in the documentation on whether Dependabot alerts are enabled by default on public repositories or not. While studying for the GHAS certification I found conflicting documentation and practice exam questions. I verified myself by going into existing private and public repositories that did not have any GHAS settings modified yet and Dependabot alerts were disabled for both.
Documentation I read for studying:
https://learn.microsoft.com/en-us/training/modules/configure-dependabot-security-updates-on-github-repo/3-dependabot-alerts
Incorrect exam prep assessment question:

https://learn.microsoft.com/en-us/credentials/certifications/github-advanced-security/practice/results?assessmentId=590484996&practice-assessment-type=certification&snapshotId=50ffe989-45a4-419e-9321-311e572a5054
This practice exam site had the correct answer for the question:
https://ghcertified.com/questions/advanced_security/question-101/
Closes:
What's being changed (if available, include any code snippets, screenshots, or gifs):
Check off the following: