Automatic Dependabot access to GitHub-hosted registries
UpdateVerifiedAdded Sep 22, 2026
Dependabot can now read from private GitHub Packages registries without a personal access token. If a package has granted your repository access through “Manage Actions access” in the package settings, Dependabot reuses that grant.
Topics: Developer tools
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Sep 9 | npm extends recovery-code security holds to all accounts Update | Update |
| Sep 9 | CodeQL 2.27.0 adds support for Linux ARM64 Update | Update |
| Sep 9 | GitHub Advanced Security expands trial availability Update | Update |
| Sep 9 | Block pull requests with exposed secrets from merging Preview | Preview |
| Sep 9 | Remediate Code Quality findings with agentic autofix Update | Update |
| Sep 10 | AI Scan for pull request APIs in public preview Preview | Preview |
| Sep 3 | Multiple trusted publishing configurations for npm GA | GA |
| Sep 15 | Enforce GitHub Advanced Security configurations Update | Update |