Skip to content

Commit a1ca7aa

Browse files
authored
Merge pull request #44083 from github/repo-sync
Repo sync
2 parents 38360ca + 1519615 commit a1ca7aa

7 files changed

Lines changed: 48 additions & 3 deletions

File tree

content/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -94,6 +94,8 @@ When you select **OIDC** as the authentication method for a private registry, ch
9494

9595
* **Azure**: Enter the **Tenant ID** (Azure AD tenant ID) and **Client ID** (Azure AD application client ID). You must configure a federated credential in Azure AD that trusts {% data variables.product.github %}'s OIDC provider.
9696
* **AWS CodeArtifact**: Enter the **AWS Region**, **Account ID** (AWS account ID), **Role Name** (IAM role name), **Domain** (CodeArtifact domain), and **Domain Owner** (CodeArtifact domain owner / AWS account ID). You can optionally provide an **Audience**. You must configure an IAM OIDC identity provider in AWS that trusts {% data variables.product.github %}'s OIDC provider.
97+
* **Cloudsmith**: Enter the **Namespace** (Cloudsmith Organization namespace), **Service Account Slug** (Cloudsmith service account slug), and **Audience** (required). You can optionally provide an **API Host** (defaults to `api.cloudsmith.io`). You must configure an OpenID Connect provider in Cloudsmith that trusts {% data variables.product.github %}'s OIDC provider.
98+
* **Google Cloud Artifact Registry**: Enter the **Workload Identity Provider** (the full resource name of the Workload Identity Provider, for example `projects/PROJECT-NUMBER/locations/global/workloadIdentityPools/POOL/providers/PROVIDER`) and **Service Account** (the email of the GCP service account to impersonate). You can optionally provide an **Audience**. You must configure a Workload Identity Pool and Provider in GCP that trusts {% data variables.product.github %}'s OIDC provider.
9799
* **JFrog Artifactory**: Enter the **OIDC Provider Name**. You can optionally provide an **Audience** and **Identity Mapping Name**.
98100

99101
The authentication type of a private registry cannot be changed after creation. To switch from OIDC to another authentication method, or vice versa, delete the existing registry and create a new one.

content/code-security/how-tos/secure-your-supply-chain/manage-your-dependency-security/configuring-access-to-private-registries-for-dependabot.md

Lines changed: 34 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -139,10 +139,12 @@ With OIDC-based authentication, {% data variables.product.prodname_dependabot %}
139139

140140
{% endif %}
141141

142-
{% data variables.product.prodname_dependabot %} supports OIDC authentication for any registry type that uses `username` and `password` authentication, when the registry is hosted on one of the following cloud providers:
142+
{% data variables.product.prodname_dependabot %} supports OIDC authentication for any registry type that uses `username` and `password` authentication, when the registry is hosted on one of the following providers:
143143

144144
* AWS CodeArtifact
145145
* Azure DevOps Artifacts
146+
* Cloudsmith
147+
* Google Cloud Artifact Registry
146148
* JFrog Artifactory
147149

148150
To configure OIDC authentication, you need to specify different values instead of `username` and `password` in your registry configuration.
@@ -177,6 +179,37 @@ registries:
177179
client-id: {% raw %}${{ secrets.AZURE_CLIENT_ID }}{% endraw %}
178180
```
179181

182+
### Cloudsmith
183+
184+
Cloudsmith requires the values `namespace`, `service-slug`, and `audience`. The `api-host` field is optional and defaults to `api.cloudsmith.io`:
185+
186+
```yaml
187+
registries:
188+
my-cloudsmith-feed:
189+
type: npm-registry
190+
url: https://dl.cloudsmith.io/MY-NAMESPACE/MY-REPOSITORY/npm/
191+
namespace: MY-NAMESPACE
192+
service-slug: MY-SERVICE-SLUG
193+
audience: https://github.com/GITHUB-ORG
194+
api-host: api.cloudsmith.io # if required by your feed
195+
```
196+
197+
### Google Cloud Artifact Registry
198+
199+
Google Cloud Artifact Registry requires the values `url` and
200+
`workload-identity-provider`. The values `service-account` and `audience` are
201+
optional:
202+
203+
```yaml
204+
registries:
205+
my-gcp-artifact-registry:
206+
type: docker-registry
207+
url: https://REGION-docker.pkg.dev
208+
workload-identity-provider: projects/PROJECT-NUMBER/locations/global/workloadIdentityPools/POOL/providers/PROVIDER
209+
service-account: SA-NAME@PROJECT-ID.iam.gserviceaccount.com # if required by your provider
210+
audience: MY-AUDIENCE # if required by your provider
211+
```
212+
180213
### JFrog Artifactory
181214

182215
JFrog Artifactory requires the values `url` and `jfrog-oidc-provider-name`. The values `audience` and `identity-mapping-name` are optional:

content/copilot/reference/copilot-billing/model-multipliers-for-annual-plans.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,8 @@ These new multipliers will **only apply** if you remain on an annual {% data var
4747

4848
Model multipliers and costs are subject to change.
4949

50+
{% data reusables.copilot.gpt-55-promo-period %}
51+
5052
| Model | Current multiplier | New multiplier |
5153
| --- | ---: | ---: |
5254
| {% for entry in tables.copilot.annual-subscriber-model-multipliers %} |

content/site-policy/other-site-policies/github-username-policy.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,11 +17,13 @@ GitHub account names are available on a first-come, first-served basis, and are
1717

1818
Keep in mind that not all activity on GitHub is publicly visible; accounts with no visible activity may be in active use.
1919

20+
We do not accept requests to release, transfer, or reclaim usernames on the basis that they appear inactive or unused. If the username you want has already been claimed, you will need to select a different available name unless you are submitting a trademark complaint as described below.
21+
2022
If the username you want has already been claimed, consider other names or unique variations. Using a number, hyphen, or an alternative spelling might help you identify a desirable username that's still available.
2123

2224
## Trademark Policy
2325

24-
If you believe someone's account is violating your trademark rights, you can find more information about making a trademark complaint on our [Trademark Policy](/site-policy/content-removal-policies/github-trademark-policy) page.
26+
If you believe someone's account is violating your trademark rights, you can find more information about making a trademark complaint on our [AUTOTITLE](/site-policy/content-removal-policies/github-trademark-policy) page. Valid trademark-related complaints are the only requests we review for possible release of a username that is already claimed.
2527

2628
## Name Squatting Policy
2729

data/release-notes/enterprise-server/3-18/8.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -71,6 +71,8 @@ sections:
7171
- |
7272
To improve page load performance, user profile pages display a maximum of 24 organizations. When viewing your own profile, a "View all" link provides access to the full list in organization settings. When viewing another user's profile, a count displays any additional organizations beyond the first 24.
7373
known_issues:
74+
- |
75+
After upgrading to 3.18.8 via hotpatch, the instance reboots and briefly enters maintenance mode. In some cases, the post-reboot configuration run fails, and the instance does not fully resume service. Site administrators who experience this should SSH into the instance and manually run `ghe-config-apply`. [Updated: 2026-04-30]
7476
- |
7577
On instances configured for high availability, you will not be able to change GitHub Actions settings through the Management Console. Other settings are not affected. [Updated: 2026-04-22]
7678
- |

data/release-notes/enterprise-server/3-20/0.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -73,7 +73,7 @@ sections:
7373
7474
# https://github.com/github/releases/issues/6437
7575
- |
76-
Secret scanning supports validity checks that indicate whether detected secrets remain active, helping teams prioritize remediation. Once enabled for a given repository, GitHub will now automatically verify secrets for alerts with supported secret types. GHES admins can make the feature available for enablement across enterprise repositories from their Management Console settings.
76+
Secret scanning supports validity checks that indicate whether detected secrets remain active, helping teams prioritize remediation. Once enabled for a given repository, GitHub will now automatically verify secrets for alerts with supported secret types. GHES admins can make the feature available for enablement across enterprise repositories from their Management Console settings. See [AUTOTITLE](/code-security/concepts/secret-security/about-validity-checks).
7777
7878
# https://github.com/github/releases/issues/6253
7979
- |

data/tables/copilot/annual-subscriber-model-multipliers.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -98,6 +98,10 @@
9898
current_multiplier: '0.33'
9999
new_multiplier: '6'
100100

101+
- model: 'GPT-5.5'
102+
current_multiplier: '7.5'
103+
new_multiplier: 'TBD'
104+
101105
- model: 'GPT-5 mini'
102106
current_multiplier: '0'
103107
new_multiplier: '0.33'

0 commit comments

Comments
 (0)