Skip to content

Commit

Permalink
Add networking requirement to Dependabot on self-hosted runners artic…
Browse files Browse the repository at this point in the history
…le (#52924)

Co-authored-by: Art Leo <[email protected]>
  • Loading branch information
mchammer01 and gitulisca authored Nov 1, 2024
1 parent 8935c41 commit e576141
Showing 1 changed file with 5 additions and 0 deletions.
Original file line number Diff line number Diff line change
@@ -1 +1,6 @@
{% data variables.product.prodname_dependabot %} runners require access to the public internet, {% data variables.product.prodname_dotcom_the_website %}, and any internal registries that will be used in {% data variables.product.prodname_dependabot_updates %}. To minimize the risk to your internal network, you should limit access from the Virtual Machine (VM) to your internal network. This reduces the potential for damage to internal systems if a runner were to download a hijacked dependency.

{% ifversion fpt or ghec %}
You must also allow outbound traffic to `dependabot-actions.githubapp.com` to prevent the jobs for {% data variables.product.prodname_dependabot_security_updates %} from failing. For more information, see "[AUTOTITLE](/actions/hosting-your-own-runners/managing-self-hosted-runners/about-self-hosted-runners#communication-between-self-hosted-runners-and-github)."

{% endif %}

0 comments on commit e576141

Please sign in to comment.