Skip to content

Update OIDC authentication section for clarity - #46033

Open
loganvolkers wants to merge 1 commit into
github:mainfrom
loganvolkers:patch-1
Open

loganvolkers wants to merge 1 commit into
github:mainfrom
loganvolkers:patch-1

Conversation

@loganvolkers

Copy link
Copy Markdown

Removed note about OIDC authentication support for organization-level private registries. This no longer appreas to be true: https://github.blog/changelog/2026-04-14-dependabot-and-code-scanning-org-level-private-registries/

Why:

Closes: #46032

What's being changed (if available, include any code snippets, screenshots, or gifs):

Removes the outdated Notes block.

Check off the following:

  • A subject matter expert (SME) has reviewed the technical accuracy of the content in this PR. In most cases, the author can be the SME. Open source contributions may require an SME review from GitHub staff.
  • The changes in this PR meet the docs fundamentals that are required for all content.
  • All CI checks are passing and the changes look good in the review environment.

Removed note about OIDC authentication support for organization-level private registries. This no longer appreas to be true: https://github.blog/changelog/2026-04-14-dependabot-and-code-scanning-org-level-private-registries/
Copilot AI balanced review requested due to automatic review settings September 23, 2026 18:24
@docs-bot docs-bot added the invalid This issue/PR is invalid label Sep 23, 2026
@docs-bot

Copy link
Copy Markdown
Collaborator

This pull request only removes existing content. Before submitting a content-removal pull request, please open an issue explaining the proposed removal and wait for approval from the GitHub Docs team. Once the change has been approved, you can open a new pull request and link it to the issue.

@github-actions

Copy link
Copy Markdown
Contributor

How to review these changes 👓

Thank you for your contribution. To review these changes, choose one of the following options:

A Hubber will need to deploy your changes internally to review.

Table of review links

Note: Please update the URL for your staging server or codespace.

The table shows the files in the content directory that were changed in this pull request. This helps you review your changes on a staging server. Changes to the data directory are not included in this table.

Source Review Production What Changed
code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries.md fpt
ghec
ghes@ 3.22 3.21 3.20 3.19 3.18
fpt
ghec
ghes@ 3.22 3.21 3.20 3.19 3.18

Key: fpt: Free, Pro, Team; ghec: GitHub Enterprise Cloud; ghes: GitHub Enterprise Server

🤖 This comment is automatically generated.

@github-actions github-actions Bot added the triage Do not begin working on this issue until triaged by the team label Sep 23, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The remaining OIDC overview still incorrectly describes the feature as Dependabot-only.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Removes an outdated note that incorrectly excluded code scanning default setup from OIDC authentication support.

Changes:

  • Deletes the obsolete OIDC limitation note.
File Description
giving-org-access-private-registries.md Removes outdated OIDC guidance.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@@ -106,9 +106,6 @@ See [AUTOTITLE](/code-security/how-tos/secure-your-supply-chain/manage-your-depe

OIDC (OpenID Connect) authentication allows {% data variables.product.prodname_dependabot %} to use short-lived credentials from your cloud identity provider to access private registries, eliminating the need to store long-lived secrets. With OIDC, credentials are generated dynamically for each {% data variables.product.prodname_dependabot %} update job. You must configure a trust relationship between your cloud provider and {% data variables.product.github %} before {% data variables.product.prodname_dependabot %} can authenticate.
@subatoi subatoi reopened this Sep 24, 2026
@subatoi subatoi added driver persona and removed triage Do not begin working on this issue until triaged by the team invalid This issue/PR is invalid labels Sep 24, 2026
@github-actions github-actions Bot added the triage Do not begin working on this issue until triaged by the team label Sep 24, 2026
@subatoi subatoi removed the triage Do not begin working on this issue until triaged by the team label Sep 24, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update OIDC authentication section for clarity

4 participants