Skip to content

How to disable for a fork? #2804

Description

@hugovk

I enabled Dependabot for a fork (https://github.com/hugovk/pytest), to make sure it was working smoothly before creating a PR to add it upstream (https://github.com/pytest-dev/pytest). Upstream is now using it, it's working well, thanks!

However, I now want to disable Dependabot for my fork but cannot find a way.

https://app.dependabot.com/accounts/hugovk says:

You've successfully migrated pytest to GitHub 🎉

image

At https://github.com/settings/installations/8631454, Dependabot Preview only has access to other repos:

image

At https://github.com/hugovk/pytest/settings/security_analysis I have everything disabled:

image

Deleting https://github.com/hugovk/pytest/blob/master/.github/dependabot.yml is not an option, because this is a fork, and it needs to be kept in sync with upstream.

How can I disable Dependabot for my fork?

Package manager/ecosystem

Python

Manifest contents prior to update

version: 2
updates:
- package-ecosystem: pip
  directory: "/testing/plugins_integration"
  schedule:
    interval: weekly
    time: "03:00"
  open-pull-requests-limit: 10
  allow:
  - dependency-type: direct
  - dependency-type: indirect

https://github.com/hugovk/pytest/blob/master/.github/dependabot.yml
https://github.com/hugovk/pytest/blob/master/testing/plugins_integration/requirements.txt


Edit: as the 2022-11-24 solution is obscured by the thousands of hidden items below, here it is for clarity:

Hmm... from when we shipped this on November 7th going forward, no repos should be default opted-in.

One exception is any repo, fork-or-no-fork will be automatically opted in if you've selected the Automatically enable for new repositories option in your user or org settings. But that's essentially inheriting a manual opt-in.

Forks that were created before November 7th will require manual disabling... we considered disabling them, but couldn't easily distinguish between those who did/didn't manually enable it from the beginning, so it was safer/more predictable for users if we left them untouched.

To disable, as @hugovk mentions above you need to either delete/re-create the fork, or click Disable on the forked repo's /settings/security_analysis page:

image

For PR's that were already sitting open when you disable Dependabot, I think nothing further happens to them unless you do it. They won't get auto-rebased or auto-closed.

Activity

  1. Mariatta commented on Dec 1, 2020

    @Mariatta

    This is happening in CPython repo as well which has 17K forks. It would help us greatly if dependabot can be disabled in forks. Thanks.

  2. feelepxyz commented on Dec 3, 2020

    @feelepxyz
    Contributor

    We're aware of this issue and planning a fix. The workaround for now is to delete the fork and re-create it without enabling Dependabot security updates. Dependabot version updates (setup from config file) isn't enabled by default on new forks but will be if security updates has ever been turned on and since disabled.

  3. patcon commented on Jan 26, 2021

    @patcon

    Thanks for clearly communicating! Any "ish" timeline on this?

    (I have unrelated issues in the forks, so deleting and recreating isn't quite as easy as it could be.)

  4. feelepxyz commented on Jan 29, 2021

    @feelepxyz
    Contributor

    @patcon we'll get to it in the next couple of months :/ going to bump it up again with the team and see if we can get to it sooner.

  5. wesinator commented on Feb 15, 2021

    @wesinator

    Getting this issue on a fork of https://github.com/EFForg/https-everywhere

    Disabling actions did not prevent new PRs being generated

  6. ldez commented on Feb 26, 2021

    @ldez

    Seems to be a duplicate of #2198

  7. added
    F: noiserelated to Dependabot being noisy, or initiatives to make Dependabot quieter
    on Apr 9, 2021
  8. trivikr commented on May 4, 2021

    @trivikr

    @feelepxyz bumping it again, as it has been three months since this comment in #2804 (comment)

    Screen Shot 2021-05-04 at 7 53 25 AM

  9. featheredtoast commented on May 20, 2021

    @featheredtoast

    The workaround also doesn't work for forks I want private because I cannot change visibility of a (Github) fork, so I'm mirroring instead. Would the solution here also allow us to disable dependabot in mirrored repositories?

  10. return42 commented on Jun 18, 2021

    @return42

    I think there is a need to act here because each fork has a master branch that cannot be changed from upstream after the fork is created. Those dependabots from forks will run infinite! At least as long as the owner of the fork does not fix his master branch what is expectable for 99% of the forks. Thinking global, this is a totally unneeded wast of resources and energy ...

  11. domenkozar commented on Jul 27, 2021

    @domenkozar

    @feelepxyz 🙏 for another bump with the team. We can't use dependabot on nixpkgs with 6.5k forks.

  12. feelepxyz commented on Jul 28, 2021

    @feelepxyz
    Contributor

    @feelepxyz 🙏 for another bump with the team. We can't use dependabot on nixpkgs with 6.5k forks.

    Thanks for raising this. We've been pretty stretched so haven't managed to get to this yet. We still want to get this fixed but can't promise a date yet.

  13. return42 commented on Jul 28, 2021

    @return42

    We've been pretty stretched

    I have understanding for this 😄 .. If you see a chance to prioritize this it would be great / IMO it is a KO criteria for projects with a huge community (a lot forks). Anyway thanks a lot for having an eye on this.

  14. ziegenberg commented on Aug 2, 2021

    @ziegenberg

    This is a REAL annoyence. It's spamming forks with unnecessary messages. Can we get this fixed rather sooner than later?

  15. 81 remaining items

  16. added a commit that references this issue on Aug 22, 2023
  17. added a commit that references this issue on Sep 6, 2023
  18. added a commit that references this issue on Oct 17, 2023
  19. added a commit that references this issue on Dec 20, 2023
  20. added a commit that references this issue on Mar 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions