Dependabot no longer infers .npmrc
Dependabot will no longer attempt to infer .npmrc configuration for npm private registries. Previously, Dependabot tried to reconstruct .npmrc contents from lockfile resolved URLs, but incorrect lockfile URLs, lockfile format differences across npm, Yarn v1, Yarn Berry, and pnpm, and other edge cases regularly caused registry authentication failures.
Read GitHub's release noteshttps://github.blog/changelog/2026-06-30-dependabot-no-longer-infers-npmrc
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Open source license compliance is in public preview
PreviewGovernanceDeveloper tools
Upcoming cloud data retention policy for closed security alerts
UpdateGovernanceSecurityDeveloper tools
Upcoming access restrictions to public API endpoints and UI views
UpdateSecurityDeveloper tools
Secret scanning adds validators for Asana, IBM, and MessageBird
UpdateSecurityObservability
Secret scanning public monitoring for enterprises
PreviewSecurityPricingObservability
npm adds preventive account protection for high-impact accounts
UpdateVector searchSecurityObservability
Self-service credential revocation for incident response
UpdateSecurityDeveloper tools
Also shipped on Jun 30, 2026
Gemini 3.1 Flash Lite Image (Nano Banana 2 Lite) is generally available
GALLMsPricingDeveloper tools
[Launched] Generally Available: Toolboxes in Microsoft Foundry
GAAI agentsDeveloper tools