From d997c72e6cc9c116ce71390fbc854cc1832018ac Mon Sep 17 00:00:00 2001 From: "Adam J. Stewart" Date: Tue, 29 Sep 2026 12:57:12 +0200 Subject: [PATCH 1/2] Dependabot: devcontainer needs root directory Signed-off-by: Adam J. Stewart --- .../supply-chain-security/dependabot-options-reference.md | 1 + 1 file changed, 1 insertion(+) diff --git a/content/code-security/reference/supply-chain-security/dependabot-options-reference.md b/content/code-security/reference/supply-chain-security/dependabot-options-reference.md index 01d39a3ada2b..2dcb44d8dbb2 100644 --- a/content/code-security/reference/supply-chain-security/dependabot-options-reference.md +++ b/content/code-security/reference/supply-chain-security/dependabot-options-reference.md @@ -301,6 +301,7 @@ The table below shows the package managers that support `cooldown`. The `default * Define directories relative to the root of the repository for most package managers. * For {% data variables.product.prodname_actions %}, use the value `/`. {% data variables.product.prodname_dependabot %} will search the `/.github/workflows` directory, as well as the `action.yml/action.yaml` file from the root directory. +* For Dev containers, use the value `/`. {% data variables.product.prodname_dependabot %} will search for the `.devcontainer.json`, `.devcontainer/devcontainer.json`, or `.devcontainer//devcontainer.json` files from the root directory. If you need to use more than one block in the configuration file to define updates for a single target branch of an ecosystem, you must ensure that all values are unique and there is no overlap in directories defined. From 0f55b13f234cdb8061f6a17cecc08886a92d9290 Mon Sep 17 00:00:00 2001 From: "Adam J. Stewart" Date: Tue, 29 Sep 2026 13:11:26 +0200 Subject: [PATCH 2/2] Grammar fixes Signed-off-by: Adam J. Stewart --- .../supply-chain-security/dependabot-options-reference.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/code-security/reference/supply-chain-security/dependabot-options-reference.md b/content/code-security/reference/supply-chain-security/dependabot-options-reference.md index 2dcb44d8dbb2..1178dca1b4f1 100644 --- a/content/code-security/reference/supply-chain-security/dependabot-options-reference.md +++ b/content/code-security/reference/supply-chain-security/dependabot-options-reference.md @@ -301,7 +301,7 @@ The table below shows the package managers that support `cooldown`. The `default * Define directories relative to the root of the repository for most package managers. * For {% data variables.product.prodname_actions %}, use the value `/`. {% data variables.product.prodname_dependabot %} will search the `/.github/workflows` directory, as well as the `action.yml/action.yaml` file from the root directory. -* For Dev containers, use the value `/`. {% data variables.product.prodname_dependabot %} will search for the `.devcontainer.json`, `.devcontainer/devcontainer.json`, or `.devcontainer//devcontainer.json` files from the root directory. +* For Dev containers, use the value `/`. {% data variables.product.prodname_dependabot %} will search the `.devcontainer.json`, `.devcontainer/devcontainer.json`, and `.devcontainer//devcontainer.json` files from the root directory. If you need to use more than one block in the configuration file to define updates for a single target branch of an ecosystem, you must ensure that all values are unique and there is no overlap in directories defined.