Board action needed: Disable org-level Dependabot security updates #36

Closed
opened 2026-03-24 16:08:13 +00:00 by privilegedescalation-cto[bot] · 1 comment
privilegedescalation-cto[bot] commented 2026-03-24 16:08:13 +00:00 (Migrated from github.com)

Problem

GitHub has auto-enabled Dependabot security update workflows on at least 3 plugin repos:

  • headlamp-polaris-plugin (workflow ID 247707067)
  • headlamp-rook-plugin
  • headlamp-sealed-secrets-plugin

These dynamic/dependabot/dependabot-updates workflows are auto-created when org-level Dependabot security updates is enabled.

Policy Conflict

Org policy (POLICIES.md) states: "We do not use Dependabot — never enable it". We use Mend Renovate exclusively. Having both active causes duplicate PRs, conflicting version pins, and confusion during security response.

Required Action (org-admin only)

A board member with org-admin access should:

  1. Go to Organization Settings → Security → Code security
  2. Disable Dependabot security updates for all repos
  3. Optionally keep Dependabot alerts (read-only) enabled if the board wants vulnerability visibility without auto-PRs

This cannot be done by any agent — it requires the GitHub org admin UI.

Tracking

Paperclip issue: PRI-803 (assigned to CTO, blocked on org-admin access)

cc @cpfarhood

## Problem GitHub has auto-enabled Dependabot security update workflows on at least 3 plugin repos: - `headlamp-polaris-plugin` (workflow ID 247707067) - `headlamp-rook-plugin` - `headlamp-sealed-secrets-plugin` These `dynamic/dependabot/dependabot-updates` workflows are auto-created when org-level Dependabot security updates is enabled. ## Policy Conflict Org policy (`POLICIES.md`) states: _"We do not use Dependabot — never enable it"_. We use Mend Renovate exclusively. Having both active causes duplicate PRs, conflicting version pins, and confusion during security response. ## Required Action (org-admin only) A board member with org-admin access should: 1. Go to **Organization Settings → Security → Code security** 2. Disable **Dependabot security updates** for all repos 3. Optionally keep **Dependabot alerts** (read-only) enabled if the board wants vulnerability visibility without auto-PRs This cannot be done by any agent — it requires the GitHub org admin UI. ## Tracking Paperclip issue: PRI-803 (assigned to CTO, blocked on org-admin access) cc @cpfarhood
privilegedescalation-cto[bot] commented 2026-03-25 11:12:03 +00:00 (Migrated from github.com)

Verified: org-level Dependabot security updates have been disabled. No Dependabot PRs or workflow runs across any repo since March 18. Closing as resolved.

Verified: org-level Dependabot security updates have been disabled. No Dependabot PRs or workflow runs across any repo since March 18. Closing as resolved.
This repo is archived. You cannot comment on issues.
1 Participants
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: privilegedescalation/org#36