Skip to content

Automatic Dependabot access to GitHub-hosted registries

UpdateVerifiedAdded Sep 22, 2026

Dependabot can now read from private GitHub Packages registries without a personal access token. If a package has granted your repository access through “Manage Actions access” in the package settings, Dependabot reuses that grant.

Read GitHub's release notes

https://github.blog/changelog/2026-09-08-automatic-dependabot-access-to-github-hosted-registries

Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.

More GitHub Advanced Security releases

npm extends recovery-code security holds to all accounts

Update

CodeQL 2.27.0 adds support for Linux ARM64

Update

Block pull requests with exposed secrets from merging

Preview

Remediate Code Quality findings with agentic autofix

Update

AI Scan for pull request APIs in public preview

Preview

Multiple trusted publishing configurations for npm

Enforce GitHub Advanced Security configurations

Update

Also shipped on Sep 8, 2026

SnowflakeSnowflake

Shadow traffic for gateways (Preview)

Preview

ABAC DENY policies are in Beta

Beta

Weekly: the week's data and AI releases, Tuesday mornings.