Repository navigation
How to disable for a fork? #2804
Description
Activity
This is happening in CPython repo as well which has 17K forks. It would help us greatly if dependabot can be disabled in forks. Thanks.
Reacted by Hugo van Kemenade, Senthil Kumaran, Michał Karzyński, Patrick Connolly, Jonathan Goble, Terence Honles, Nicolas DUBIEN, Will Beason, Miro Hrončok, Matthew Leather and 16 moreWe're aware of this issue and planning a fix. The workaround for now is to delete the fork and re-create it without enabling Dependabot security updates. Dependabot version updates (setup from config file) isn't enabled by default on new forks but will be if security updates has ever been turned on and since disabled.
Reacted by Mariatta, Ülgen Sarıkavak, Marc Mueller, Patrick Connolly, Stefan Neuhaus, Alexandre Flament, Jarek Radosz, Queen Vinyl Da.i'gyu-Kazotetsu, Will Beason, Christopher Sahnwaldt and 3 moreReacted by Leo Fang, Christopher Sahnwaldt, Ali Caglayan, Matthew Leather, Matt Johnston, Lee Verberne, Hugo van Kemenade and JulietteReacted by Josh Soref, Jonathan Goble, Ralf Gommers, Christopher Sahnwaldt, Val Lorentz, Ali Caglayan, Hugo van Kemenade and Elan RuusamäeThanks for clearly communicating! Any "ish" timeline on this?
(I have unrelated issues in the forks, so deleting and recreating isn't quite as easy as it could be.)
Reacted by Josh Soref and Nicolas DUBIEN@patcon we'll get to it in the next couple of months :/ going to bump it up again with the team and see if we can get to it sooner.
Reacted by Leo Fang, Christopher Sahnwaldt, Ali Caglayan and DasSkelettReacted by Ville Skyttä, Radek Antoniuk, Rylan Polster, AnomalRoil, David Petersen and Christopher SahnwaldtReacted by Patrick Connolly, Markus Rodler, Rylan Polster, Tom Hayward, Stefan Neuhaus, Josh Soref, James Skimming, Daniel Ziegenberg and Christopher SahnwaldtGetting this issue on a fork of https://github.com/EFForg/https-everywhere
Disabling actions did not prevent new PRs being generated
Reacted by Travis Plunk, Oliver Kopp and Oliver B. FischerSeems to be a duplicate of #2198
Reacted by Patrick Connolly and Alexander Popov- addedF: noiserelated to Dependabot being noisy, or initiatives to make Dependabot quieterrelated to Dependabot being noisy, or initiatives to make Dependabot quieter
on Apr 9, 2021 @feelepxyz bumping it again, as it has been three months since this comment in #2804 (comment)
Reacted by Fabian Köstring, Bartosz Klonowski, Dmitrii Ustiugov, Darius Kazemi, Soitora, DrDaveD, Adam Lewandowski, dhruv., Akihiro Suda, Christopher Sahnwaldt and 8 moreThe workaround also doesn't work for forks I want private because I cannot change visibility of a (Github) fork, so I'm mirroring instead. Would the solution here also allow us to disable dependabot in mirrored repositories?
Reacted by Lukas Geiger, Jarek Radosz, Tomachi, Denis Rouzaud, Will Beason, Ulrich Petri, Ivan Mironov and Antoni SpaandermanI think there is a need to act here because each fork has a master branch that cannot be changed from upstream after the fork is created. Those dependabots from forks will run infinite! At least as long as the owner of the fork does not fix his master branch what is expectable for 99% of the forks. Thinking global, this is a totally unneeded wast of resources and energy ...
Reacted by Soitora, Will Beason, Hugo van Kemenade, Christopher Sahnwaldt, Colin Robbins, Dmitry Murzin, Waridley, Ivan Mironov, Erin Schnabel, Robert Stoll and 7 more@feelepxyz 🙏 for another bump with the team. We can't use dependabot on nixpkgs with 6.5k forks.
Reacted by Piotrek Żygieło, Fabian Köstring, Benoit de Chezelles, Android, Markus Heiser, Hugo van Kemenade, Matthew Leather and Nico Korthout@feelepxyz 🙏 for another bump with the team. We can't use dependabot on nixpkgs with 6.5k forks.
Thanks for raising this. We've been pretty stretched so haven't managed to get to this yet. We still want to get this fixed but can't promise a date yet.
Reacted by Patrick Connolly and AndroidWe've been pretty stretched
I have understanding for this 😄 .. If you see a chance to prioritize this it would be great / IMO it is a KO criteria for projects with a huge community (a lot forks). Anyway thanks a lot for having an eye on this.
Reacted by Hugo van KemenadeThis is a REAL annoyence. It's spamming forks with unnecessary messages. Can we get this fixed rather sooner than later?
Reacted by Akihiro Suda, Gunnar Liljas, Andy Snell, Dennis Welu, Alexis Georges, Diego Heras, Travis Plunk, Hugo van Kemenade, Pauli Järvinen, Markus Heiser and 5 more81 remaining items
- added 2 commits that reference this issue
on Jun 8, 2023 - added 2 commits that reference this issue
on Feb 24, 2024 - addedL: dockerDocker containersDocker containersL: git:submodulesGit submodulesGit submodulesL: go:modulesGolang modulesGolang modulesL: ruby:bundlerRubyGems via bundlerRubyGems via bundler
on Jul 2, 2024

I enabled Dependabot for a fork (https://github.com/hugovk/pytest), to make sure it was working smoothly before creating a PR to add it upstream (https://github.com/pytest-dev/pytest). Upstream is now using it, it's working well, thanks!
However, I now want to disable Dependabot for my fork but cannot find a way.
https://app.dependabot.com/accounts/hugovk says:
At https://github.com/settings/installations/8631454, Dependabot Preview only has access to other repos:
At https://github.com/hugovk/pytest/settings/security_analysis I have everything disabled:
Deleting https://github.com/hugovk/pytest/blob/master/.github/dependabot.yml is not an option, because this is a fork, and it needs to be kept in sync with upstream.
How can I disable Dependabot for my fork?
Package manager/ecosystem
Python
Manifest contents prior to update
https://github.com/hugovk/pytest/blob/master/.github/dependabot.yml
https://github.com/hugovk/pytest/blob/master/testing/plugins_integration/requirements.txt
Edit: as the 2022-11-24 solution is obscured by the thousands of hidden items below, here it is for clarity: