Automatic Dependabot access to GitHub-hosted registries
Dependabot can now read from private GitHub Packages registries without a personal access token. If a package has granted your repository access through “Manage Actions access” in the package settings, Dependabot reuses that grant.
Read GitHub's release noteshttps://github.blog/changelog/2026-09-08-automatic-dependabot-access-to-github-hosted-registries
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
npm extends recovery-code security holds to all accounts
UpdateSecurityObservability
GitHub Advanced Security expands trial availability
UpdateSecurityPricingObservability
Remediate Code Quality findings with agentic autofix
UpdateAI agentsGovernancePricing
AI Scan for pull request APIs in public preview
PreviewSecurityObservabilityDeveloper tools
Enforce GitHub Advanced Security configurations
UpdateGovernanceSecurityObservability
Also shipped on Sep 8, 2026
Incremental ingestion for Salesforce formula fields in Lakeflow Connect will soon be generally available
GAPricingData integrationPerformance