telexed ~ c / 324fdd40-96fradar:50 · infra_saasLIVE
← back
NO.
#324fdd40
Topic
INFRA & SAAS
Source
GitHub Changelog
Published
2026-05-19 17:41:04
Importance
★ 5/10 — radar 50
GitHub expands OIDC for `Dependabot` and code scanning private registries
FIG-3241:1

GitHub expands OIDC for `Dependabot` and code scanning private registries

Org-level private registry auth now covers two more artifact providers. Useful if your supply-chain checks already pull private packages; otherwise low urgency.

[ KEY POINTS ]
  1. Cloudsmith and Google Artifact Registry join org-level OIDC auth support for private registries, reducing long-lived secret handling.
  2. Coverage applies to Dependabot and code scanning, so dependency updates and security analysis can access private packages with the same auth model.
  3. Best fit is repos already using private artifacts. For public-package-only projects, this is a cleanup item, not a roadmap changer.
Originalgithub.blog/changelog/2026-05-19-expanded-oidc-support-for-dependabot-and-code-scanningRead original →

// related