-
Notifications
You must be signed in to change notification settings - Fork 65.9k
Closed as not planned
Labels
contentThis issue or pull request belongs to the Docs Content teamThis issue or pull request belongs to the Docs Content teamtriageDo not begin working on this issue until triaged by the teamDo not begin working on this issue until triaged by the team
Description
Code of Conduct
- I have read and agree to the GitHub Docs project's Code of Conduct
What article on docs.github.com is affected?
https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#commit-message--
https://docs.github.com/en/code-security/concepts/supply-chain-security/about-dependabot-security-updates
What part(s) of the article would you like to see updated?
For security updates: All commit messages follow the defined pattern, unless target-branch defines updates to a non-default branch.
However, this other page: https://docs.github.com/en/code-security/concepts/supply-chain-security/about-dependabot-security-updates
Suggests that
There is no interaction between the settings specified in the dependabot.yml file and Dependabot security alerts,```
This seems unclear. One source states that commit messages for security updates follow a defined pattern unless updates target a non-default branch. The other source says Dependabot security updates are not affected by settings in `dependabot.yml`, except for alert closure when related pull requests are merged.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
contentThis issue or pull request belongs to the Docs Content teamThis issue or pull request belongs to the Docs Content teamtriageDo not begin working on this issue until triaged by the teamDo not begin working on this issue until triaged by the team