Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. GitHub Actions workflows triggered by Dependabot use Dependabot secrets, not ordinary GitHub Actions secrets. For the documented Dependabot events, GITHUB_TOKEN is read-only by default. To let a workflow authenticate to a private package registry, create the credential as a repository or organization Dependabot secret and reference it with the usual secrets.NAME syntax.

Which secrets and token permissions does a Dependabot workflow use?

For workflows initiated by dependabot[bot] through pull_request, pull_request_review, pull_request_review_comment, push, create, deployment, or deployment_status, GitHub documents this behavior:

  • GITHUB_TOKEN has read-only permissions by default.
  • Secrets are populated from Dependabot secrets.
  • GitHub Actions secrets are not available to the run.

That means a credential created only in the repository’s Actions secrets will not populate ${{ secrets.NAME }} in one of these runs. The same expression can be used for a Dependabot secret, but the secret must be stored in the Dependabot secret store. See GitHub’s Dependabot on GitHub Actions documentation.

Workflow case GITHUB_TOKEN Secret source and availability Untrusted update code
Documented Dependabot-triggered events: pull_request, pull_request_review, pull_request_review_comment, push, create, deployment, and deployment_status Read-only by default Dependabot secrets are available; Actions secrets are not Dependabot updates may involve changed dependency content. Treat pull-request code and data as untrusted.
pull_request_target when the pull request base ref was created by Dependabot Read-only No secrets are available The event runs in a security-sensitive context; do not use it to expose credentials to untrusted update code.

The second row is a specific exception, not a way to make ordinary Actions secrets available. GitHub identifies the case by the pull request base-ref creator being dependabot[bot]; its documented expression is github.event.pull_request.user.login == 'dependabot[bot]'. Review the event and permission details before choosing a trigger.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How do you give a Dependabot workflow private-registry access?

  1. Create a Dependabot secret. Add the registry credential under the repository’s Dependabot secrets, or configure it as an organization Dependabot secret and grant access to the repository.
  2. Reference it in the workflow. Use the regular secrets context, for example:
    env:
      PRIVATE_REGISTRY_TOKEN: ${{ secrets.PRIVATE_REGISTRY_TOKEN }}
  3. Use the value only where required. Pass it to the package manager or registry login step, and avoid printing it in logs. The secret name in the workflow must match the name configured in Dependabot secrets.

GitHub documents repository- and organization-level Dependabot secrets, with organization secrets restrictable to selected repositories, in Understanding secret types and using secrets in a workflow. Its private registry guidance also explains that Dependabot secrets can supply credentials needed by workflows triggered by Dependabot pull requests.

Why are Actions secrets empty on a Dependabot pull request?

Because GitHub deliberately supplies Dependabot secrets, rather than GitHub Actions secrets, to these workflows. If a workflow expression such as ${{ secrets.PRIVATE_REGISTRY_TOKEN }} resolves to an empty value on a Dependabot run, first check whether the credential was added to Dependabot secrets. For the Dependabot-created-base-ref pull_request_target case, no secrets are available at all, so moving the credential between stores will not make it available to that run.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Changing workflow permissions does not change which secret store GitHub uses. Token write permissions and secret availability are separate controls; do not assume a permissions change will expose Actions secrets or override the pull_request_target restriction.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why is the token read-only, and when did this behavior begin?

GitHub documents read-only GITHUB_TOKEN permissions by default for the listed Dependabot-triggered events, and read-only access with no secrets in the specified pull_request_target case. These restrictions limit the authority available to workflows associated with dependency updates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

GitHub announced on November 30, 2021 that Actions workflows triggered by Dependabot would receive Dependabot secrets. The stated aim was to let CI access private package registries using credentials already configured for Dependabot. The current documentation describes the event behavior and the distinction between secret stores.

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.