Skip to content

Clarify Dependabot default ecosystem label behavior and naming - #46248

Open
alok-108 wants to merge 1 commit into
github:mainfrom
alok-108:fix-dependabot-ecosystem-default-labels
Open

alok-108 wants to merge 1 commit into
github:mainfrom
alok-108:fix-dependabot-ecosystem-default-labels

Conversation

@alok-108

@alok-108 alok-108 commented Oct 10, 2026 •

Copy link
Copy Markdown

Why:

Closes: #46230

Resolves contradictions between dependabot-options-reference.md and data/reusables/dependabot/default-labels.md:

  1. Dependabot applies both the dependencies label and the ecosystem label to all pull requests (including single-ecosystem updates), not just when more than one package manager is defined.
  2. The default label created and applied for GitHub Actions is github_actions (with an underscore), not github-actions.

What's being changed:

  • data/reusables/dependabot/default-labels.md: Fixed the example ecosystem label for GitHub Actions from github-actions to github_actions.
  • content/code-security/reference/supply-chain-security/dependabot-options-reference.md: Updated the default behavior description under labels to state that the ecosystem label is added to all pull requests, including single-ecosystem updates (aligning with default-labels.md and observed Dependabot behavior), and referenced github_actions.

Check off the following:

  • A subject matter expert (SME) has reviewed the technical accuracy of the content in this PR. In most cases, the author can be the SME. Open source contributions may require an SME review from GitHub staff.
  • The changes in this PR meet the docs fundamentals that are required for all content.
  • All CI checks are passing and the changes look good in the review environment.

@github-actions github-actions Bot added the triage Do not begin working on this issue until triaged by the team label Oct 10, 2026
@github-actions

Copy link
Copy Markdown
Contributor

How to review these changes 👓

Thank you for your contribution. To review these changes, choose one of the following options:

A Hubber will need to deploy your changes internally to review.

Table of review links

Note: Please update the URL for your staging server or codespace.

The table shows the files in the content directory that were changed in this pull request. This helps you review your changes on a staging server. Changes to the data directory are not included in this table.

Source Review Production What Changed
code-security/reference/supply-chain-security/dependabot-options-reference.md fpt
ghec
ghes@ 3.22 3.21 3.20 3.19 3.18
fpt
ghec
ghes@ 3.22 3.21 3.20 3.19 3.18
code-security/tutorials/secure-your-dependencies/customizing-dependabot-prs.md fpt
ghec
ghes@ 3.22 3.21 3.20 3.19 3.18
fpt
ghec
ghes@ 3.22 3.21 3.20 3.19 3.18
from reusable

Key: fpt: Free, Pro, Team; ghec: GitHub Enterprise Cloud; ghes: GitHub Enterprise Server

🤖 This comment is automatically generated.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

triage Do not begin working on this issue until triaged by the team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dependabot docs disagree on when the ecosystem label is added, and on its name (github-actions vs github_actions)

1 participant