Skip to content

Dependabot no longer infers .npmrc

UpdateVerifiedAdded Sep 22, 2026

Dependabot will no longer attempt to infer .npmrc configuration for npm private registries. Previously, Dependabot tried to reconstruct .npmrc contents from lockfile resolved URLs, but incorrect lockfile URLs, lockfile format differences across npm, Yarn v1, Yarn Berry, and pnpm, and other edge cases regularly caused registry authentication failures.

Read GitHub's release notes

https://github.blog/changelog/2026-06-30-dependabot-no-longer-infers-npmrc

Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.

More GitHub Advanced Security releases

GitHub code coverage merge protection for pull requests

Preview

Upcoming cloud data retention policy for closed security alerts

Update

Secret scanning public monitoring for enterprises

Preview

Self-service credential revocation for incident response

Update

Also shipped on Jun 30, 2026

SnowflakeSnowflake

Analytical search (Public Preview)

Preview

Lakehouse Real-Time (Beta)

Beta

Gemini Omni Flash in public preview

Preview

Weekly: the week's data and AI releases, Tuesday mornings.