docs icon indicating copy to clipboard operation
docs copied to clipboard

Add Dependabot permissions warnings

Open Marcono1234 opened this issue 8 months ago • 8 comments

Why:

Dependabot intentionally has no built-in automerge feature (https://github.com/dependabot/dependabot-core/issues/1973#issuecomment-640918321), and in the past permissions for Dependabot workflows were changed to read-only by default (changelog entry).

If I understand it correctly, the concern is that a Dependabot workflow with write permissions could be exploited by a compromised dependency to immediately compromise the consuming repository as soon as the Dependabot PR is created, without any interaction of the owner.

Therefore adding a custom automerge workflow for Dependabot or giving its workflows write permissions can be a security risk, and is probably worth pointing out in the documentation.

Slightly related to #37657, but does not resolve it

What's being changed (if available, include any code snippets, screenshots, or gifs):

Add warnings to the documentation to inform users about the risk of giving Dependabot workflows more permissions.

I hope these warnings do not seem like fear mongering (any feedback regarding wording is welcome!). Maybe some users who set up auto merging of Dependabot PRs might not consider this a big issue (or an issue at all).

Check off the following:

  • [ ] A subject matter expert (SME) has reviewed the technical accuracy of the content in this PR. In most cases, the author can be the SME. Open source contributions may require an SME review from GitHub staff.
  • [ ] The changes in this PR meet the docs fundamentals that are required for all content.
  • [ ] All CI checks are passing and the changes look good in the review environment.

Marcono1234 avatar Apr 23 '25 16:04 Marcono1234

How to review these changes 👓

Thank you for your contribution. To review these changes, choose one of the following options:

A Hubber will need to deploy your changes internally to review.

Table of review links

⚠️ Warning: Our review server is experiencing latency issues.

The table shows the files in the content directory that were changed in this pull request. This helps you review your changes on the review server. Changes to the data directory are not included in this table.

Source Review Production What Changed
code-security/dependabot/troubleshooting-dependabot/troubleshooting-dependabot-on-github-actions.md fpt
ghec
ghes@ 3.16 3.15 3.14 3.13 3.12
fpt
ghec
ghes@ 3.16 3.15 3.14 3.13 3.12
code-security/dependabot/working-with-dependabot/automating-dependabot-with-github-actions.md fpt
ghec
ghes@ 3.16 3.15 3.14 3.13 3.12
fpt
ghec
ghes@ 3.16 3.15 3.14 3.13 3.12

Key: fpt: Free, Pro, Team; ghec: GitHub Enterprise Cloud; ghes: GitHub Enterprise Server

🤖 This comment is automatically generated.

github-actions[bot] avatar Apr 23 '25 16:04 github-actions[bot]

Please let me know if I am misunderstanding the security risk here, or if you would like the warnings to be changed.

Marcono1234 avatar Apr 23 '25 16:04 Marcono1234

Naa man I will repair it as soon as I reach home

On Wed, Apr 23, 2025, 9:23 PM Marcono1234 @.***> wrote:

Marcono1234 left a comment (github/docs#37733) https://github.com/github/docs/pull/37733#issuecomment-2824837847

Please let me know if I am misunderstanding the security risk here, or if you would like the warnings to be changed.

— Reply to this email directly, view it on GitHub https://github.com/github/docs/pull/37733#issuecomment-2824837847, or unsubscribe https://github.com/notifications/unsubscribe-auth/BC6Y7BBGNIN2D5FIZW2IAWT2265ARAVCNFSM6AAAAAB3WY7T62VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDQMRUHAZTOOBUG4 . You are receiving this because you are subscribed to this thread.Message ID: @.***>

changeschung avatar Apr 23 '25 18:04 changeschung

Thanks and you make some changes if u like

On Wed, Apr 23, 2025, 11:44 PM Danial Mehdi @.***> wrote:

Naa man I will repair it as soon as I reach home

On Wed, Apr 23, 2025, 9:23 PM Marcono1234 @.***> wrote:

Marcono1234 left a comment (github/docs#37733) https://github.com/github/docs/pull/37733#issuecomment-2824837847

Please let me know if I am misunderstanding the security risk here, or if you would like the warnings to be changed.

— Reply to this email directly, view it on GitHub https://github.com/github/docs/pull/37733#issuecomment-2824837847, or unsubscribe https://github.com/notifications/unsubscribe-auth/BC6Y7BBGNIN2D5FIZW2IAWT2265ARAVCNFSM6AAAAAB3WY7T62VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDQMRUHAZTOOBUG4 . You are receiving this because you are subscribed to this thread.Message ID: @.***>

changeschung avatar Apr 23 '25 18:04 changeschung

@Marcono1234 Thanks for opening these! I'll get this triaged and look for an SME to review the specifics. We appreciate the time you're investing to improve the documentation. 💛

Sharra-writes avatar Apr 23 '25 19:04 Sharra-writes

Thanks for opening a pull request! We've triaged this issue for technical review by a subject matter expert :eyes:

github-actions[bot] avatar Apr 23 '25 19:04 github-actions[bot]

Q

Annanft avatar Apr 30 '25 19:04 Annanft

This is a gentle bump for the docs team that this PR is waiting for technical review.

github-actions[bot] avatar May 29 '25 16:05 github-actions[bot]

This is a gentle bump for the docs team that this PR is waiting for technical review.

github-actions[bot] avatar Jun 29 '25 16:06 github-actions[bot]

This is a gentle reminder for the docs team that this PR is waiting for technical review by a subject matter expert.

github-actions[bot] avatar Jul 30 '25 16:07 github-actions[bot]

A stale label has been added to this pull request because it has been open 30 days with no activity. If you think this pull request should remain open, please add a new comment.

github-actions[bot] avatar Sep 02 '25 16:09 github-actions[bot]

This is a gentle reminder for the docs team that this PR is waiting for technical review by a subject matter expert.

github-actions[bot] avatar Oct 15 '25 16:10 github-actions[bot]