From 654abe4dc95faf0a6138e6e78400ec10df2410d1 Mon Sep 17 00:00:00 2001 From: Anthony Swierkosz Date: Tue, 29 Mar 2022 23:15:10 -0400 Subject: [PATCH 1/5] Update permissions metadata to include users and teams with explicit access --- .../dependabot-alerts/viewing-and-updating-dependabot-alerts.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/code-security/dependabot/dependabot-alerts/viewing-and-updating-dependabot-alerts.md b/content/code-security/dependabot/dependabot-alerts/viewing-and-updating-dependabot-alerts.md index 02b5b1a801..ee496cf6eb 100644 --- a/content/code-security/dependabot/dependabot-alerts/viewing-and-updating-dependabot-alerts.md +++ b/content/code-security/dependabot/dependabot-alerts/viewing-and-updating-dependabot-alerts.md @@ -6,7 +6,7 @@ redirect_from: - /github/managing-security-vulnerabilities/viewing-and-updating-vulnerable-dependencies-in-your-repository - /code-security/supply-chain-security/viewing-and-updating-vulnerable-dependencies-in-your-repository - /code-security/supply-chain-security/managing-vulnerabilities-in-your-projects-dependencies/viewing-and-updating-vulnerable-dependencies-in-your-repository -permissions: Repository administrators and organization owners can view and update dependencies. +permissions: Repository administrators and organization owners can view and update dependencies as well as users and teams with explicit access. shortTitle: View Dependabot alerts versions: fpt: '*' From fc1231d83d945881bd937090dd4dc3249b3f7e62 Mon Sep 17 00:00:00 2001 From: Anthony Swierkosz Date: Tue, 29 Mar 2022 23:52:01 -0400 Subject: [PATCH 2/5] Inform users of permission requirement for dependabot alerts --- data/reusables/repositories/sidebar-dependabot-alerts.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/reusables/repositories/sidebar-dependabot-alerts.md b/data/reusables/repositories/sidebar-dependabot-alerts.md index fdeed8b963..a2de913791 100644 --- a/data/reusables/repositories/sidebar-dependabot-alerts.md +++ b/data/reusables/repositories/sidebar-dependabot-alerts.md @@ -1,2 +1,2 @@ -1. In the security sidebar, click **{% data variables.product.prodname_dependabot_alerts %}**.{% ifversion fpt or ghec %} +1. In the security sidebar, click **{% data variables.product.prodname_dependabot_alerts %}**. If this option is missing, then you do not have access to security alerts and will need to be given access. For more information, see "[Managing security and analysis settings for your repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-security-and-analysis-settings-for-your-repository#granting-access-to-security-alerts)."{% ifversion fpt or ghec %} ![{% data variables.product.prodname_dependabot_alerts %} tab](/assets/images/help/repository/dependabot-alerts-tab.png){% else %}![{% data variables.product.prodname_dependabot_alerts %} tab](/assets/images/enterprise/repository/dependabot-alerts-tab.png){% endif %} From 0e453941273d576e44543dc63d883f56bb02bfe3 Mon Sep 17 00:00:00 2001 From: mc <42146119+mchammer01@users.noreply.github.com> Date: Fri, 1 Apr 2022 10:16:33 +0100 Subject: [PATCH 3/5] Apply suggestions from code review --- .../dependabot-alerts/viewing-and-updating-dependabot-alerts.md | 2 +- data/reusables/repositories/sidebar-dependabot-alerts.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/content/code-security/dependabot/dependabot-alerts/viewing-and-updating-dependabot-alerts.md b/content/code-security/dependabot/dependabot-alerts/viewing-and-updating-dependabot-alerts.md index ee496cf6eb..72209a136e 100644 --- a/content/code-security/dependabot/dependabot-alerts/viewing-and-updating-dependabot-alerts.md +++ b/content/code-security/dependabot/dependabot-alerts/viewing-and-updating-dependabot-alerts.md @@ -6,7 +6,7 @@ redirect_from: - /github/managing-security-vulnerabilities/viewing-and-updating-vulnerable-dependencies-in-your-repository - /code-security/supply-chain-security/viewing-and-updating-vulnerable-dependencies-in-your-repository - /code-security/supply-chain-security/managing-vulnerabilities-in-your-projects-dependencies/viewing-and-updating-vulnerable-dependencies-in-your-repository -permissions: Repository administrators and organization owners can view and update dependencies as well as users and teams with explicit access. +permissions: Repository administrators and organization owners can view and update dependencies, as well as users and teams with explicit access. shortTitle: View Dependabot alerts versions: fpt: '*' diff --git a/data/reusables/repositories/sidebar-dependabot-alerts.md b/data/reusables/repositories/sidebar-dependabot-alerts.md index a2de913791..4183d71bb3 100644 --- a/data/reusables/repositories/sidebar-dependabot-alerts.md +++ b/data/reusables/repositories/sidebar-dependabot-alerts.md @@ -1,2 +1,2 @@ -1. In the security sidebar, click **{% data variables.product.prodname_dependabot_alerts %}**. If this option is missing, then you do not have access to security alerts and will need to be given access. For more information, see "[Managing security and analysis settings for your repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-security-and-analysis-settings-for-your-repository#granting-access-to-security-alerts)."{% ifversion fpt or ghec %} +1. In the security sidebar, click **{% data variables.product.prodname_dependabot_alerts %}**. If this option is missing, it means you don't have access to security alerts and need to be given access. For more information, see "[Managing security and analysis settings for your repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-security-and-analysis-settings-for-your-repository#granting-access-to-security-alerts)."{% ifversion fpt or ghec %} ![{% data variables.product.prodname_dependabot_alerts %} tab](/assets/images/help/repository/dependabot-alerts-tab.png){% else %}![{% data variables.product.prodname_dependabot_alerts %} tab](/assets/images/enterprise/repository/dependabot-alerts-tab.png){% endif %} From 0dfddc9de23d4e8d412b20d733a246c5bc642dc2 Mon Sep 17 00:00:00 2001 From: hubwriter Date: Fri, 1 Apr 2022 10:37:46 +0100 Subject: [PATCH 4/5] Update development.md --- contributing/development.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/contributing/development.md b/contributing/development.md index 62aa369c75..3cd1373b95 100644 --- a/contributing/development.md +++ b/contributing/development.md @@ -32,7 +32,7 @@ Note that `npm ci` and `npm run build` are steps that should typically only need ### Using GitHub Codespaces -As an alternative, you can simply use [GitHub Codespaces](https://github.com/features/codespaces). +As an alternative, you can simply use [GitHub Codespaces](https://docs.github.com/en/codespaces/overview). For more information about using a codespace for working on GitHub documentation, see "[Working in a codespace](https://github.com/github/docs/blob/main/contributing/codespace.md)." In a matter of minutes, you will be ready to edit, preview and test your changes directly from the comfort of your browser. From ea9bd6276354f13df1d34f170de814d25fc856b3 Mon Sep 17 00:00:00 2001 From: hubwriter Date: Fri, 1 Apr 2022 10:39:26 +0100 Subject: [PATCH 5/5] Update CONTRIBUTING.md --- CONTRIBUTING.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 6f8590caa3..afe91a311f 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -42,6 +42,10 @@ Click **Make a contribution** at the bottom of any docs page to make small chang +#### Make changes in a codespace + +For more information about using a codespace for working on GitHub documentation, see "[Working in a codespace](https://github.com/github/docs/blob/main/contributing/codespace.md)." + #### Make changes locally 1. [Install Git LFS](https://docs.github.com/en/github/managing-large-files/versioning-large-files/installing-git-large-file-storage). @@ -54,9 +58,6 @@ Click **Make a contribution** at the bottom of any docs page to make small chang - Using the command line: - [Fork the repo](https://docs.github.com/en/github/getting-started-with-github/fork-a-repo#fork-an-example-repository) so that you can make your changes without affecting the original project until you're ready to merge them. -- GitHub Codespaces: - - [Fork, edit, and preview](https://docs.github.com/en/free-pro-team@latest/github/developing-online-with-codespaces/creating-a-codespace) using [GitHub Codespaces](https://github.com/features/codespaces) without having to install and run the project locally. - 3. Install or update to **Node.js v16**. For more information, see [the development guide](contributing/development.md). 4. Create a working branch and start with your changes!