Guidance and recommendations for working with Dependabot, such as managing pull requests raised by Dependabot, using GitHub Actions with Dependabot, and troubleshooting Dependabot errors.
You manage pull requests raised by Dependabot in much the same way as other pull requests, but there are some extra options.
Examples of how you can use GitHub Actions to automate common Dependabot related tasks.
You can use Dependabot to keep the actions you use updated to the latest versions.
You can configure Dependabot to access dependencies stored in private registries. You can store authentication information, like passwords and access tokens, as encrypted secrets and then reference these in the Dependabot configuration file.
This article contains detailed information about configuring private registries, as well as commands you can run from the command line to configure your package managers locally.
Examples of how you can configure Dependabot to only access private registries by removing calls to public registries.
If the dependency information reported by GitHub Enterprise Server is not what you expected, there are a number of points to consider, and various things you can check.
Sometimes Dependabot is unable to raise a pull request to update your dependencies. You can review the error and unblock Dependabot.