Skip to content

Commit 8ceedbb

Browse files
authored
Merge pull request #46131 from github/repo-sync
Repo sync
2 parents 394068d + f187b6c commit 8ceedbb

76 files changed

Lines changed: 1215 additions & 599 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/actions/cache-nextjs/action.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,4 +15,4 @@ runs:
1515
key: ${{ runner.os }}-nextjs-${{ hashFiles('**/package-lock.json') }}-${{ hashFiles('**/*.ts', '**/*.tsx') }}
1616
# If source files changed but packages didn't, rebuild from a prior cache.
1717
restore-keys: |
18-
${{ runner.os }}-nextjs-v13-${{ hashFiles('**/package-lock.json') }}-
18+
${{ runner.os }}-nextjs-${{ hashFiles('**/package-lock.json') }}-

‎.github/workflows/moda-ci.yaml‎

Lines changed: 28 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -11,25 +11,30 @@ on:
1111
merge_group:
1212
types: [checks_requested]
1313

14+
permissions: {}
15+
1416
jobs:
1517
##########################
1618
# Generate Vault keys
1719
##########################
1820
set-vault-keys:
21+
permissions: {}
1922
runs-on: ubuntu-latest
2023
outputs:
2124
modified_vault_keys: ${{ steps.modify_vault_keys.outputs.modified }}
2225
steps:
2326
- name: Set vault-keys output
2427
id: modify_vault_keys
28+
env:
29+
VAULT_KEYS: ${{ vars.VAULT_KEYS }}
2530
run: |
26-
if [ -z "${{ vars.VAULT_KEYS }}" ]; then
31+
if [ -z "$VAULT_KEYS" ]; then
2732
# We want to add the DOCS_BOT_PAT_BASE to the list of keys
2833
# so that builds fetch the secret from the docs-internal vault
2934
# where --environment is "ci"
30-
echo "modified=DOCS_BOT_PAT_BASE" >> $GITHUB_OUTPUT
35+
echo "modified=DOCS_BOT_PAT_BASE" >> "$GITHUB_OUTPUT"
3136
else
32-
echo "modified=${{ vars.VAULT_KEYS }},DOCS_BOT_PAT_BASE" >> $GITHUB_OUTPUT
37+
echo "modified=${VAULT_KEYS},DOCS_BOT_PAT_BASE" >> "$GITHUB_OUTPUT"
3338
fi
3439
3540
#############
@@ -39,6 +44,13 @@ jobs:
3944
if: ${{ github.repository == 'github/docs-internal' }}
4045
name: ${{ matrix.ci_job.job }}
4146
needs: set-vault-keys
47+
permissions:
48+
actions: read
49+
attestations: write
50+
checks: read
51+
contents: read
52+
id-token: write
53+
statuses: read
4254
strategy:
4355
fail-fast: false
4456
matrix:
@@ -58,6 +70,13 @@ jobs:
5870
if: ${{ github.repository == 'github/docs-internal' }}
5971
name: ${{ matrix.ci_job.job }}
6072
needs: set-vault-keys
73+
permissions:
74+
actions: read
75+
attestations: write
76+
checks: read
77+
contents: read
78+
id-token: write
79+
statuses: read
6180
strategy:
6281
fail-fast: false
6382
matrix:
@@ -80,6 +99,12 @@ jobs:
8099
if: ${{ github.repository == 'github/docs-internal' }}
81100
name: ${{ matrix.ci_job.job }}
82101
needs: set-vault-keys
102+
permissions:
103+
actions: read
104+
checks: read
105+
contents: read
106+
id-token: write
107+
statuses: read
83108
strategy:
84109
fail-fast: false
85110
matrix:
@@ -93,11 +118,3 @@ jobs:
93118
secrets:
94119
dx-bot-token: ${{ secrets.INTERNAL_ACTIONS_DX_BOT_ACCOUNT_TOKEN }}
95120
datadog-api-key: ${{ secrets.DATADOG_API_KEY }}
96-
97-
permissions:
98-
actions: read
99-
checks: read
100-
contents: read
101-
statuses: read
102-
id-token: write
103-
attestations: write

‎.github/zizmor.yml‎

Lines changed: 0 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,13 +4,6 @@ rules:
44
dangerous-triggers:
55
disable: true
66

7-
# moda-ci uses reusable workflows (uses:) which don't support job-level
8-
# permissions. id-token:write and attestations:write are needed by docker-image
9-
# for attestation but can't be scoped to that job alone.
10-
excessive-permissions:
11-
ignore:
12-
- moda-ci.yaml
13-
147
# actions/* has immutable tags, so ref-pinning is sufficient.
158
# github/internal-actions is a private GitHub org repo, ref-pin is fine.
169
# Everything else must be hash-pinned.

‎content/admin/managing-accounts-and-repositories/managing-organizations-in-your-enterprise/custom-properties.md‎

Lines changed: 14 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,6 @@
11
---
22
title: Custom properties
33
intro: 'Custom properties allow you to add structured metadata to repositories and organizations, enabling better organization, governance, and automation across your {% data variables.product.github %} environment.'
4-
permissions: 'Repository custom properties can be managed by organization owners and users with admin permissions to the repository. Organization custom properties can be managed by enterprise owners and users with the "Manage the Enterprise''s custom properties definitions" permission.'
54
versions:
65
ghec: '*'
76
ghes: '>= 3.21'
@@ -15,15 +14,11 @@ category:
1514

1615
Custom properties are structured metadata fields that you can attach to repositories or organizations in {% data variables.location.product_location %}. They allow you to decorate your repositories or organizations with information such as compliance frameworks, data sensitivity, or project details.
1716

18-
An enterprise can have up to 100 property definitions. An allowed value list can have up to 200 items.
19-
2017
There are two types of custom properties:
2118

2219
* **Repository custom properties**: Metadata attached to individual repositories.
2320
* **Organization custom properties**: Metadata attached to organizations within an enterprise.
2421

25-
{% data reusables.enterprise-accounts.org-custom-properties-public-preview %}
26-
2722
## What are the benefits of using custom properties?
2823

2924
As well as providing improved discovery, automated workflows, compliance tracking, targeted policy enforcement, and better reporting capabilities, custom properties enable powerful governance through **ruleset integration**.
@@ -35,10 +30,20 @@ Both repository and organization custom properties can be used as targeting crit
3530

3631
## How do I add and manage custom properties?
3732

38-
{% ifversion ghec %}
33+
There are multiple ways to manage custom properties. To manage properties within {% data variables.product.github %}, you can use:
3934

40-
Custom properties are fully supported through {% data variables.product.github %}'s REST API, enabling programmatic management and integration with external systems. See [AUTOTITLE](/rest/enterprise-admin/custom-properties).
35+
* Your organization or enterprise settings. See [AUTOTITLE](/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization) and [AUTOTITLE](/admin/managing-accounts-and-repositories/managing-organizations-in-your-enterprise/managing-custom-properties-for-organizations).
36+
* {% data variables.product.github %}'s [AUTOTITLE](/rest/enterprise-admin/custom-properties).
4137

42-
{% endif %}
38+
{% ifversion external-custom-properties %}
39+
40+
You can also set up an integration to automatically update custom properties with metadata from an external system, such as a software catalog or internal developer portal. External properties can be used in the same places as standard repository custom properties. See [AUTOTITLE](/organizations/managing-organization-settings/sync-external-custom-properties)
4341

44-
You can add custom properties through {% data variables.product.github %}'s UI. See [AUTOTITLE](/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization) and [AUTOTITLE](/admin/managing-accounts-and-repositories/managing-organizations-in-your-enterprise/managing-custom-properties-for-organizations).
42+
Both standard custom properties and external properties can be managed at scale with the REST API and {% data variables.product.prodname_github_apps %}. External properties are more suitable when the external system should be the source of truth, because they are:
43+
44+
* Namespaced (`external_system.property_name`), so their provenance is clear and they don't conflict with other custom properties in the organization.
45+
* Read-only on {% data variables.product.github %}, so users cannot edit them and bring them out of line with the external system.
46+
47+
External properties are **not** available for organization custom properties (metadata attached to organizations).
48+
49+
{% endif %}

‎content/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/managing-custom-properties-for-repositories-in-your-enterprise.md‎

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,19 @@ When you create a single-select or multi-select property, {% data variables.prod
4242
This feature is available with {% data variables.copilot.copilot_business_short %} or {% data variables.copilot.copilot_enterprise_short %}. By default, suggestions are enabled for enterprise-level properties and each organization can decide whether to enable suggestions. Enterprise owners can instead enable or disable suggestions everywhere with the **Repository custom property suggestions** policy. See [AUTOTITLE](/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-enterprise-policies).
4343
{% endif %}
4444

45-
## Adding custom properties
45+
{% ifversion external-custom-properties %}
46+
47+
## Syncing custom properties with an external system
48+
49+
> [!NOTE] {% data reusables.organizations.external-properties-preview %}
50+
51+
{% data reusables.organizations.external-properties-intro %}
52+
53+
External custom properties are configured separately for each organization. For setup instructions, see [AUTOTITLE](/organizations/managing-organization-settings/sync-external-custom-properties).
54+
55+
{% endif %}
56+
57+
## Adding custom properties on {% data variables.product.github %}
4658

4759
You can add custom properties to your enterprise to make those properties available in all of your organizations.
4860

‎content/code-security/concepts/supply-chain-security/dependabot-on-actions.md‎

Lines changed: 17 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,14 +39,28 @@ You may see workflow runs named `dynamic/dependabot/dependabot-updates` or check
3939
You can run {% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} using:
4040
* **Standard {% data variables.product.prodname_dotcom %}-hosted runners.** These are the default runners used by {% data variables.product.github %} to execute {% data variables.product.prodname_actions %} jobs.
4141
* **{% data variables.actions.hosted_runners_caps %}.** These are {% data variables.product.prodname_dotcom %}-hosted runners with advanced features like more RAM, CPU, and disk space. For more information, see [AUTOTITLE](/actions/how-tos/manage-runners/larger-runners).
42-
* **Self-hosted runners.** These runners grant you greater control over {% data variables.product.prodname_dependabot %} access to your private registries and internal network resources. Be aware that for security reasons, {% data variables.product.prodname_dependabot_updates %} on self-hosted runners will not run on public repositories. For more information on assigning a `dependabot` label on self-hosted runners, see [AUTOTITLE](/code-security/how-tos/secure-your-supply-chain/manage-your-dependency-security/configure-on-self-hosted-runners).
42+
* **Self-hosted runners.** These runners grant you greater control over {% data variables.product.prodname_dependabot %} access to your private registries and internal network resources. Be aware that for security reasons, {% data variables.product.prodname_dependabot_updates %} on self-hosted runners will not run on public repositories. For more information on assigning labels to self-hosted runners, see [AUTOTITLE](/code-security/how-tos/secure-your-supply-chain/manage-your-dependency-security/configure-on-self-hosted-runners).
4343

4444
Running {% data variables.product.prodname_dependabot %} on standard {% data variables.product.prodname_dotcom %}-hosted or self-hosted runners **does not** count towards your included {% data variables.product.prodname_actions %} minutes. For {% data variables.product.prodname_dependabot %} on {% data variables.actions.hosted_runners %}, {% data variables.product.prodname_dotcom %} will bill your organization at the regular rate. See [AUTOTITLE](/billing/reference/actions-runner-pricing).
4545

4646
{% data reusables.dependabot.vnet-arc-note %}
4747

4848
## How runner settings interact
4949

50+
{% ifversion dependabot-repository-runner-settings %}
51+
52+
You can select a runner type for {% data variables.product.prodname_dependabot %} at the organization or repository level:
53+
54+
* **Standard {% data variables.product.company_short %} runner** uses the default {% data variables.product.company_short %}-hosted environment.
55+
* **Labeled runner** sends jobs to self-hosted or {% data variables.actions.hosted_runners %} that match the configured label. If you do not specify a label, {% data variables.product.prodname_dependabot %} uses the `dependabot` label. You can also specify a runner group to limit jobs to matching runners in that group.
56+
57+
> [!WARNING]
58+
> If the specified runner group does not exist, {% data variables.product.prodname_dependabot %} reports an error immediately. If the group exists but no online runner in the group matches the configured label, the job remains queued until a matching runner is available. Make sure the repository can access the specified runner group.
59+
60+
Labeled runners are not available for public repositories. These repositories use standard {% data variables.product.company_short %}-hosted runners.
61+
62+
{% else %}
63+
5064
The {% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} runners and {% data variables.product.prodname_dependabot %} on self-hosted runners settings are interdependent:
5165

5266
* Enabling "{% data variables.product.prodname_dependabot %} on self-hosted runners" automatically enables "{% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} runners". Disabling "{% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} runners" automatically disables "{% data variables.product.prodname_dependabot %} on self-hosted runners".
@@ -55,6 +69,8 @@ The {% data variables.product.prodname_dependabot %} on {% data variables.produc
5569
> [!WARNING]
5670
> If both settings are enabled but no self-hosted runners or {% data variables.actions.hosted_runners %} with a `dependabot` label are available, {% data variables.product.prodname_dependabot %} jobs will remain queued indefinitely. Ensure runners with this label are configured before enabling "{% data variables.product.prodname_dependabot %} on self-hosted runners".
5771
72+
{% endif %}
73+
5874
## Access and permissions
5975

6076
If you are transitioning to using {% data variables.product.prodname_dependabot %} on {% data variables.product.prodname_actions %} runners and you restrict access to your organization's or repository's private resources, you may need to update your list of allowed IP addresses. For example, if you currently limit access to your private resources to the IP addresses that {% data variables.product.prodname_dependabot %} uses, you should update your allowlist to use the {% data variables.product.prodname_dotcom %}-hosted runners IP addresses sourced from the meta API endpoint. For more information, see [AUTOTITLE](/rest/meta).

‎content/code-security/how-tos/find-and-fix-code-vulnerabilities/manage-your-configuration/edit-default-setup.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -101,7 +101,7 @@ The recommended way to customize default setup at scale is to set an organizatio
101101

102102
We recommend testing the configuration file on a single repository before setting the organization-wide default. See [AUTOTITLE](/code-security/concepts/code-scanning/repository-properties#testing-changes-before-applying-them).
103103

104-
1. The configuration file will be automatically detected and merged with the configuration default setup generates the next time {% data variables.product.prodname_code_scanning %} runs on each repository in the organization. Repositories that already have an explicit value set for the `github-codeql-config-file` property continue to use that value instead of the organization-wide default. For more information about how default and explicit repository property values interact, see [AUTOTITLE](/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization#adding-custom-properties).
104+
1. The configuration file will be automatically detected and merged with the configuration default setup generates the next time {% data variables.product.prodname_code_scanning %} runs on each repository in the organization. Repositories that already have an explicit value set for the `github-codeql-config-file` property continue to use that value instead of the organization-wide default. For more information about how default and explicit repository property values interact, see [AUTOTITLE](/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization#adding-custom-properties-on-github).
105105

106106
### Applying a configuration file to a repository
107107

‎content/code-security/how-tos/secure-at-scale/configure-organization-security/establish-complete-coverage/configure-global-settings.md‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ For more information, see [AUTOTITLE](/code-security/concepts/supply-chain-secur
6060

6161
### Configuring the runner type for {% data variables.product.prodname_dependabot %}
6262

63-
You can configure which type of runner {% data variables.product.prodname_dependabot %} uses to scan for version and security updates. By default, {% data variables.product.prodname_dependabot %} uses standard **{% data variables.product.company_short %}-hosted runners**. You can configure {% data variables.product.prodname_dependabot %} to use **self-hosted runners** with custom labels, which allows you to integrate with existing runner infrastructure such as {% data variables.product.prodname_actions_runner_controller %} (ARC).
63+
You can configure which type of runner {% data variables.product.prodname_dependabot %} uses to scan for version and security updates. By default, {% data variables.product.prodname_dependabot %} uses standard **{% data variables.product.company_short %}-hosted runners**. You can configure {% data variables.product.prodname_dependabot %} to use **labeled runners**, which allows you to integrate with existing runner infrastructure such as {% data variables.product.prodname_actions_runner_controller %} (ARC).
6464

6565
> [!NOTE]
6666
> * For security reasons, {% data variables.product.prodname_dependabot %} uses {% data variables.product.company_short %}-hosted runners for public repositories, even when you configure labeled runners.
@@ -71,9 +71,9 @@ To configure the runner type:
7171
1. Under "{% data variables.product.prodname_dependabot %}", next to "Runner type", select {% octicon "pencil" aria-label="Edit runner type" %}.
7272
1. In the "Edit runner type for {% data variables.product.prodname_dependabot %}" dialog, select the runner type you want {% data variables.product.prodname_dependabot %} to use:
7373
* **Standard {% data variables.product.company_short %} runner**.
74-
* **Labeled runner**: If you select this option, {% data variables.product.prodname_dependabot %} will use self-hosted runners that match the label you specify.
74+
* **Labeled runner**: If you select this option, {% data variables.product.prodname_dependabot %} will use {% ifversion fpt or ghec %}self-hosted or {% data variables.actions.hosted_runners %}{% else %}self-hosted runners{% endif %} that match the label you specify.
7575
1. If you selected **Labeled runner**:
76-
* In "Runner label", enter the label assigned to your self-hosted runners. {% data variables.product.prodname_dependabot %} will use runners with this label. By default, the `dependabot` label is used, but you can specify a custom label to match your existing runner infrastructure.
76+
* In "Runner label", enter the label assigned to your runners. {% data variables.product.prodname_dependabot %} will use runners with this label. By default, the `dependabot` label is used, but you can specify a custom label to match your existing runner infrastructure.
7777
* Optionally, in "Runner group name", enter the name of a runner group if you want to target a specific group of runners.
7878
1. Click **Save runner selection**.
7979

‎content/code-security/how-tos/secure-your-supply-chain/manage-your-dependency-security/configure-on-github-hosted-runners.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,13 @@ If you restrict access to your organization's or repository's private resources,
2525
{% data reusables.repositories.navigate-to-repo %}
2626
{% data reusables.repositories.sidebar-settings %}
2727
{% data reusables.repositories.navigate-to-code-security-and-analysis %}
28+
{% ifversion dependabot-repository-runner-settings %}
29+
1. Under "Dependency scanning", in the "{% data variables.product.prodname_dependabot %} version updates" section, next to "Runner type", click {% octicon "pencil" aria-label="Edit runner type" %}.
30+
1. From the "Runner type" dropdown menu, select **Standard {% data variables.product.github %} runner**.
31+
1. Click **Save runner selection**.
32+
{% else %}
2833
1. Under "Dependabot", to the right of "{% data variables.product.prodname_dependabot %} on Actions runners", click **Enable** to enable the feature or **Disable** to disable it.
34+
{% endif %}
2935

3036
{% data reusables.dependabot.no-ubuntu-latest-label-self-hosted %}
3137

0 commit comments

Comments
 (0)