product1 publisher
Dependabot now authenticates to GHCR with the same token Actions already carries
The PAT in dependabot.yml can finally come out, but only after an admin adds the repository to the package's Manage Actions access list, and GitHub keeps the old credential working, leaving half-done migrations indistinguishable from finished ones.
Publishers:devops.com
Reality
- Evidence45
- Adoption25
- Hype gap0
- Incentives55
- Confidence50