Dependabot no longer infers .npmrc
UpdateVerifiedAdded Sep 22, 2026
Dependabot will no longer attempt to infer .npmrc configuration for npm private registries. Previously, Dependabot tried to reconstruct .npmrc contents from lockfile resolved URLs, but incorrect lockfile URLs, lockfile format differences across npm, Yarn v1, Yarn Berry, and pnpm, and other edge cases regularly caused registry authentication failures.
Topics: Observability
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Jun 30 | GitHub code coverage merge protection for pull requests Preview | Preview |
| Jun 30 | Open source license compliance is in public preview Preview | Preview |
| Jun 30 | Upcoming cloud data retention policy for closed security alerts Update | Update |
| Jun 30 | Upcoming access restrictions to public API endpoints and UI views Update | Update |
| Jul 1 | Secret scanning adds validators for Asana, IBM, and MessageBird Update | Update |
| Jul 2 | Secret scanning public monitoring for enterprises Preview | Preview |
| Jun 25 | npm adds preventive account protection for high-impact accounts Update | Update |
| Jun 24 | Self-service credential revocation for incident response Update | Update |