30 lines
1.9 KiB
Markdown
30 lines
1.9 KiB
Markdown
---
|
||
source_url: https://github.blog/changelog/2026-06-30-dependabot-no-longer-infers-npmrc/
|
||
ingested: 2026-06-30
|
||
sha256: 6d011665e0dca4deeb537df366a3663297746d55e2829994a9872bce0317ad69
|
||
discovered_from:
|
||
platform: discord
|
||
channel_id: '1028287639918497822'
|
||
channel_name: chat
|
||
message_id: '1521533588019871885'
|
||
author_id: '890908900520505354'
|
||
posted_at: 2026-06-30T15:11:16.111000000Z
|
||
message_excerpt: "https://github.blog/changelog/2026-06-30-dependabot-no-longer-infers-npmrc/"
|
||
---
|
||
[Back to changelog](https://github.blog/changelog/)
|
||
|
||
Dependabot will no longer attempt to infer `.npmrc` configuration for npm private registries. Previously, Dependabot tried to reconstruct `.npmrc` contents from lockfile `resolved` URLs, but incorrect lockfile URLs, lockfile format differences across npm, Yarn v1, Yarn Berry, and pnpm, and other edge cases regularly caused registry authentication failures.
|
||
|
||
### What’s changing
|
||
|
||
You can now define a `scope` property on registries in your `dependabot.yml`. Dependabot uses this to automatically generate the correct `.npmrc`. When `scope` is provided, it takes precedence over all other `.npmrc` sources, including any committed `.npmrc` file in your repository. This makes `dependabot.yml` the authoritative source for registry configuration.
|
||
|
||
If your repository already includes a checked-in `.npmrc` and you have **not** configured `scope`, Dependabot will continue to use it. The `scope` property is only needed when you don’t have a committed `.npmrc` and are relying on Dependabot’s inference.
|
||
|
||
### Who can use this feature
|
||
|
||
This feature is available for all github.com users and will ship in GHES 3.23.
|
||
|
||
### Get started
|
||
|
||
Review the [Dependabot configuration docs](https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file) and update your `dependabot.yml` to add `scope` to any npm registries that need it. |