Dependabot: trust individual external code registries #33750
Unanswered
TALlama
asked this question in
Code Security
Replies: 1 comment
-
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
The
insecure-external-code-execution
setting in the Dependabot docs lets the update checker trust external code registries.But it's an all-or-nothing switch right now: if we
allow
it, we are implicitly trusting all registries that might get added in the future. Currently you make that decision once, based on the registries you have now, and never have to worry about it again.We would prefer it if each registry could be trusted individually. When we add a new registry, we'd see the trust assertion in the PR and have to think about if we actually do trust it. We'd be regularly reminded that this part of our supply chain is potentially exploitable.
Beta Was this translation helpful? Give feedback.
All reactions