The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Yes. GitHub Actions workflows triggered by Dependabot use Dependabot secrets, not ordinary GitHub Actions secrets. For the documented Dependabot events, GITHUB_TOKEN is read-only by default. To let a workflow authenticate to a private package registry, create the credential as a repository or organization Dependabot secret and reference it with the usual secrets.NAME syntax.
Which secrets and token permissions does a Dependabot workflow use?
For workflows initiated by dependabot[bot] through pull_request, pull_request_review, pull_request_review_comment, push, create, deployment, or deployment_status, GitHub documents this behavior:
GITHUB_TOKENhas read-only permissions by default.- Secrets are populated from Dependabot secrets.
- GitHub Actions secrets are not available to the run.
That means a credential created only in the repository’s Actions secrets will not populate ${{ secrets.NAME }} in one of these runs. The same expression can be used for a Dependabot secret, but the secret must be stored in the Dependabot secret store. See GitHub’s Dependabot on GitHub Actions documentation.
| Workflow case | GITHUB_TOKEN |
Secret source and availability | Untrusted update code |
|---|---|---|---|
Documented Dependabot-triggered events: pull_request, pull_request_review, pull_request_review_comment, push, create, deployment, and deployment_status |
Read-only by default | Dependabot secrets are available; Actions secrets are not | Dependabot updates may involve changed dependency content. Treat pull-request code and data as untrusted. |
pull_request_target when the pull request base ref was created by Dependabot |
Read-only | No secrets are available | The event runs in a security-sensitive context; do not use it to expose credentials to untrusted update code. |
The second row is a specific exception, not a way to make ordinary Actions secrets available. GitHub identifies the case by the pull request base-ref creator being dependabot[bot]; its documented expression is github.event.pull_request.user.login == 'dependabot[bot]'. Review the event and permission details before choosing a trigger.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How do you give a Dependabot workflow private-registry access?
- Create a Dependabot secret. Add the registry credential under the repository’s Dependabot secrets, or configure it as an organization Dependabot secret and grant access to the repository.
- Reference it in the workflow. Use the regular secrets context, for example:
env: PRIVATE_REGISTRY_TOKEN: ${{ secrets.PRIVATE_REGISTRY_TOKEN }} - Use the value only where required. Pass it to the package manager or registry login step, and avoid printing it in logs. The secret name in the workflow must match the name configured in Dependabot secrets.
GitHub documents repository- and organization-level Dependabot secrets, with organization secrets restrictable to selected repositories, in Understanding secret types and using secrets in a workflow. Its private registry guidance also explains that Dependabot secrets can supply credentials needed by workflows triggered by Dependabot pull requests.
Why are Actions secrets empty on a Dependabot pull request?
Because GitHub deliberately supplies Dependabot secrets, rather than GitHub Actions secrets, to these workflows. If a workflow expression such as ${{ secrets.PRIVATE_REGISTRY_TOKEN }} resolves to an empty value on a Dependabot run, first check whether the credential was added to Dependabot secrets. For the Dependabot-created-base-ref pull_request_target case, no secrets are available at all, so moving the credential between stores will not make it available to that run.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Changing workflow permissions does not change which secret store GitHub uses. Token write permissions and secret availability are separate controls; do not assume a permissions change will expose Actions secrets or override the pull_request_target restriction.
Why is the token read-only, and when did this behavior begin?
GitHub documents read-only GITHUB_TOKEN permissions by default for the listed Dependabot-triggered events, and read-only access with no secrets in the specified pull_request_target case. These restrictions limit the authority available to workflows associated with dependency updates.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
GitHub announced on November 30, 2021 that Actions workflows triggered by Dependabot would receive Dependabot secrets. The stated aim was to let CI access private package registries using credentials already configured for Dependabot. The current documentation describes the event behavior and the distinction between secret stores.
Quick Recap
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

