add
This commit is contained in:
@@ -0,0 +1,30 @@
|
||||
---
|
||||
source_url: https://github.blog/changelog/2026-06-30-dependabot-no-longer-infers-npmrc/
|
||||
ingested: 2026-06-30
|
||||
sha256: 6d011665e0dca4deeb537df366a3663297746d55e2829994a9872bce0317ad69
|
||||
discovered_from:
|
||||
platform: discord
|
||||
channel_id: '1028287639918497822'
|
||||
channel_name: chat
|
||||
message_id: '1521533588019871885'
|
||||
author_id: '890908900520505354'
|
||||
posted_at: 2026-06-30T15:11:16.111000000Z
|
||||
message_excerpt: "https://github.blog/changelog/2026-06-30-dependabot-no-longer-infers-npmrc/"
|
||||
---
|
||||
[Back to changelog](https://github.blog/changelog/)
|
||||
|
||||
Dependabot will no longer attempt to infer `.npmrc` configuration for npm private registries. Previously, Dependabot tried to reconstruct `.npmrc` contents from lockfile `resolved` URLs, but incorrect lockfile URLs, lockfile format differences across npm, Yarn v1, Yarn Berry, and pnpm, and other edge cases regularly caused registry authentication failures.
|
||||
|
||||
### What’s changing
|
||||
|
||||
You can now define a `scope` property on registries in your `dependabot.yml`. Dependabot uses this to automatically generate the correct `.npmrc`. When `scope` is provided, it takes precedence over all other `.npmrc` sources, including any committed `.npmrc` file in your repository. This makes `dependabot.yml` the authoritative source for registry configuration.
|
||||
|
||||
If your repository already includes a checked-in `.npmrc` and you have **not** configured `scope`, Dependabot will continue to use it. The `scope` property is only needed when you don’t have a committed `.npmrc` and are relying on Dependabot’s inference.
|
||||
|
||||
### Who can use this feature
|
||||
|
||||
This feature is available for all github.com users and will ship in GHES 3.23.
|
||||
|
||||
### Get started
|
||||
|
||||
Review the [Dependabot configuration docs](https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file) and update your `dependabot.yml` to add `scope` to any npm registries that need it.
|
||||
Reference in New Issue
Block a user