At organization scope, enabling Dependabot alerts broadly applies the feature to the organization's eligible repositories, rather than limiting it solely to private repositories or repositories licensed for the broader GitHub Advanced Security product. Dependabot alerts support public, private, and internal repositories, subject to repository eligibility and applicable organization or enterprise configuration. GitHub's current documentation describes organization-level management as enabling Dependabot alerts across all eligible repositories through security configurations. The feature is distinct from licensed GitHub Code Security or Secret Protection capabilities, so the setting is not restricted merely to repositories where those products are enabled. Consequently, All repositories is the intended answer in the supplied choices, with the practical qualification that GitHub applies the configuration to repositories that are eligible for the feature.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit