Files
llm-wiki/raw/articles/github-dependabot-npmrc-scope-2026.md
T
2026-07-03 00:38:05 +09:00

30 lines
1.9 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
source_url: https://github.blog/changelog/2026-06-30-dependabot-no-longer-infers-npmrc/
ingested: 2026-06-30
sha256: 6d011665e0dca4deeb537df366a3663297746d55e2829994a9872bce0317ad69
discovered_from:
platform: discord
channel_id: '1028287639918497822'
channel_name: chat
message_id: '1521533588019871885'
author_id: '890908900520505354'
posted_at: 2026-06-30T15:11:16.111000000Z
message_excerpt: "https://github.blog/changelog/2026-06-30-dependabot-no-longer-infers-npmrc/"
---
[Back to changelog](https://github.blog/changelog/)
Dependabot will no longer attempt to infer `.npmrc` configuration for npm private registries. Previously, Dependabot tried to reconstruct `.npmrc` contents from lockfile `resolved` URLs, but incorrect lockfile URLs, lockfile format differences across npm, Yarn v1, Yarn Berry, and pnpm, and other edge cases regularly caused registry authentication failures.
### What’s changing
You can now define a `scope` property on registries in your `dependabot.yml`. Dependabot uses this to automatically generate the correct `.npmrc`. When `scope` is provided, it takes precedence over all other `.npmrc` sources, including any committed `.npmrc` file in your repository. This makes `dependabot.yml` the authoritative source for registry configuration.
If your repository already includes a checked-in `.npmrc` and you have **not** configured `scope`, Dependabot will continue to use it. The `scope` property is only needed when you don’t have a committed `.npmrc` and are relying on Dependabot’s inference.
### Who can use this feature
This feature is available for all github.com users and will ship in GHES 3.23.
### Get started
Review the [Dependabot configuration docs](https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file) and update your `dependabot.yml` to add `scope` to any npm registries that need it.