Code Monkey home page Code Monkey logo

Comments (9)

lindan-betterment avatar lindan-betterment commented on July 27, 2024

I am experiencing the same issue.

from fetch-metadata.

mwaddell avatar mwaddell commented on July 27, 2024

@SalimBensiali your repository is not configured to use Dependabot security updates and alerts:

image

I updated the README (see #187) to make it explicit that this feature relies upon those being enabled. My apologies for the confusion.

from fetch-metadata.

SalimBensiali avatar SalimBensiali commented on July 27, 2024

@mwaddell my repo does have dependabot security updates and alerts enabled. Look at any previously closed dependabot alerts via the auto merge workflow https://github.com/SalimBensiali/le-blanc-jewellery/pulls?q=is%3Apr+is%3Aclosed

The issue I am reporting relates the v1.3.0 new feature alert-lookup

from fetch-metadata.

SalimBensiali avatar SalimBensiali commented on July 27, 2024

I think you simply don't have the permissions to view them
image

from fetch-metadata.

SalimBensiali avatar SalimBensiali commented on July 27, 2024

@mwaddell I managed to run the dry-run command which successfully returned the missing metadata for me.
image

Could it be because your LOCAL_GITHUB_ACCESS_TOKEN does not give you permission to access the data? Which would be consistent with not seeing that dependabot security alerts and updates are enabled on https://github.com/SalimBensiali/le-blanc-jewellery/security.

from fetch-metadata.

SalimBensiali avatar SalimBensiali commented on July 27, 2024

The docs you are linking to in #187 (https://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts#access-to--dependabot-alerts) do explain why you could not see any dependabot alerts on my repo.

By default, we notify people with admin permissions in the affected repositories about new Dependabot alerts. GitHub never publicly discloses identified vulnerabilities for any repository. You can also make Dependabot alerts visible to additional people or teams working repositories that you own or have admin permissions for. For more information, see "Managing security and analysis settings for your repository."

This is further confirmed here.

from fetch-metadata.

SalimBensiali avatar SalimBensiali commented on July 27, 2024

@mwaddell you could run the dry-run command off main and my branch and target a test repo you own to verify the bug and the fix. All you need is a repo with a manifest file in the root directory and any dependabot PR.

from fetch-metadata.

mwaddell avatar mwaddell commented on July 27, 2024

Thank you for the additional clarification - I understand now. Thank you for the PR and for updating all the unit tests, I've reviewed and approved the changes for @brrygrdn to merge.

from fetch-metadata.

SalimBensiali avatar SalimBensiali commented on July 27, 2024

👍

from fetch-metadata.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.