Update Dependabot alerts notification settings details#41791
Update Dependabot alerts notification settings details#41791mlkaufman14 wants to merge 1 commit intogithub:mainfrom
Conversation
How to review these changes 👓Thank you for your contribution. To review these changes, choose one of the following options: A Hubber will need to deploy your changes internally to review. Table of review linksNote: Please update the URL for your staging server or codespace. The table shows the files in the
Key: fpt: Free, Pro, Team; ghec: GitHub Enterprise Cloud; ghes: GitHub Enterprise Server 🤖 This comment is automatically generated. |
|
@mlkaufman14 I don't see any documentation that's in our actual docs (from GitHub, not Microsoft) saying that notifications aren't enabled in public repositories by default, so I'm going to have to make sure it's expected behavior and not a bug. If there were conflicts in GitHub's documentation, I would just accept it, but if the GitHub documentation is consistent and the Microsoft documentation isn't, Microsoft may be observing what's happening in some cases rather than describing what should be happening. |
|
A stale label has been added to this pull request because it has been open 30 days with no activity. If you think this pull request should remain open, please add a new comment. |
|
A stale label has been added to this pull request because it has been open 30 days with no activity. If you think this pull request should remain open, please add a new comment. |
Copied text from this documentation: https://learn.microsoft.com/en-us/training/modules/configure-dependabot-security-updates-on-github-repo/3-dependabot-alerts
Why:
There is mixed information in the documentation on whether Dependabot alerts are enabled by default on public repositories or not. While studying for the GHAS certification I found conflicting documentation and practice exam questions. I verified myself by going into existing private and public repositories that did not have any GHAS settings modified yet and Dependabot alerts were disabled for both.
Documentation I read for studying:
https://learn.microsoft.com/en-us/training/modules/configure-dependabot-security-updates-on-github-repo/3-dependabot-alerts
Incorrect exam prep assessment question:

https://learn.microsoft.com/en-us/credentials/certifications/github-advanced-security/practice/results?assessmentId=590484996&practice-assessment-type=certification&snapshotId=50ffe989-45a4-419e-9321-311e572a5054
This practice exam site had the correct answer for the question:
https://ghcertified.com/questions/advanced_security/question-101/
Closes:
What's being changed (if available, include any code snippets, screenshots, or gifs):
Check off the following: