This commit is contained in:
2026-07-03 00:38:05 +09:00
parent 87eacd39b2
commit 86cad348b4
149 changed files with 24450 additions and 105 deletions
@@ -0,0 +1,30 @@
---
source_url: https://github.blog/changelog/2026-06-30-dependabot-no-longer-infers-npmrc/
ingested: 2026-06-30
sha256: 6d011665e0dca4deeb537df366a3663297746d55e2829994a9872bce0317ad69
discovered_from:
platform: discord
channel_id: '1028287639918497822'
channel_name: chat
message_id: '1521533588019871885'
author_id: '890908900520505354'
posted_at: 2026-06-30T15:11:16.111000000Z
message_excerpt: "https://github.blog/changelog/2026-06-30-dependabot-no-longer-infers-npmrc/"
---
[Back to changelog](https://github.blog/changelog/)
Dependabot will no longer attempt to infer `.npmrc` configuration for npm private registries. Previously, Dependabot tried to reconstruct `.npmrc` contents from lockfile `resolved` URLs, but incorrect lockfile URLs, lockfile format differences across npm, Yarn v1, Yarn Berry, and pnpm, and other edge cases regularly caused registry authentication failures.
### What’s changing
You can now define a `scope` property on registries in your `dependabot.yml`. Dependabot uses this to automatically generate the correct `.npmrc`. When `scope` is provided, it takes precedence over all other `.npmrc` sources, including any committed `.npmrc` file in your repository. This makes `dependabot.yml` the authoritative source for registry configuration.
If your repository already includes a checked-in `.npmrc` and you have **not** configured `scope`, Dependabot will continue to use it. The `scope` property is only needed when you don’t have a committed `.npmrc` and are relying on Dependabot’s inference.
### Who can use this feature
This feature is available for all github.com users and will ship in GHES 3.23.
### Get started
Review the [Dependabot configuration docs](https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file) and update your `dependabot.yml` to add `scope` to any npm registries that need it.