Dependabot Secrets

Dependabot and Actions Secrets Together

Dependabot 29 's pull requests (Dependabot Version Updates) trigger CI like any other, but since a malicious update could try to steal credentials, workflows Dependabot triggers through push or pull_request events get a read-only GITHUB_TOKEN and no Actions secrets. They see only Dependabot secrets, a separate store read with the same secrets.NAME syntax, which Dependabot also uses to reach private registries.

Listing the repository's Dependabot secrets with this book's tokenShell
gh secret list --app dependabot
Output
failed to get secrets: HTTP 403: Resource not accessible by personal access token
  (https://api.github.com/
repos/binarybehemoth/booknest/dependabot/secrets?per_page=100)

The token lacks the Dependabot secrets permission, so this store is not run here (gh 29 secret set NAME --app dependabot would fill it). BookNest needs none, because ci.yml uses no secrets. When a workflow does, store the name in both stores, skip the step with if: github.actor != 'dependabot[bot]', or move the privileged part to a workflow that runs after merge. Avoid pull_request_target, which lifts the restrictions (Triggers).