Docs
Reference

GitHub Dependabot organization secrets

Registry credentials for every repository in an organization, or only its private ones. The sync never changes which repositories reach a secret that already exists.

Registry credentials for every repository in an organization, or only its private ones. The sync never changes which repositories reach a secret that already exists.

The connection

WhatThis provider
VendorGitHub
Keygithub-dependabot-org-secrets
Availabilityavailable. You can connect it today.
Credential penv holdsgithub-token
Values read backno
Activationimmediate

What it moves

DirectionWhat it does
exportWrites names and values from penv into the store.

GitHub returns no value once it holds one, so penv can write here and cannot read back.

When a written value goes live

immediate. The running app sees a new value at once.

What happens to a name that exists

DirectionPolicies you can pick
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

How you connect

You paste a credential you already hold. penv seals it and never shows it again.

FieldLabelKindRequiredWhat it is
tokenAccess tokensecret, masked here and sealedyesNeeds admin:org. A repository-scoped token cannot reach the organization store.

What a mapping asks for

Answered once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
organizationOrganizationtextyesnoThe organization whose Dependabot store this environment maps onto.
visibilityWhich repositorieschoiceyesyesPrivate is the narrowest useful choice. All means every repository in the organization. One of Private and internal repositories, Every repository in the organization. Starts at private.

Permissions it needs

penv probes for these when it verifies the connection.

PermissionDirectionsBlockingWithout it
user:readevery directionyesWe cannot confirm which GitHub account this token belongs to.
admin:orgevery directionyesDependabot organization secrets need an organization admin token. A repository token cannot reach them.