Skip to content

Conflicting info regarding open PR limit for Dependabot security updates #46116

Description

@FaithOmbongi

Code of Conduct

What article on docs.github.com is affected?

Dependabot TSG: Pull request limit reached error vs. dependabot.yml options reference: open-pull-requests-limit key

What part(s) of the article would you like to see updated?

The dependabot.yml reference has this note: "Security update pull requests are not subject to this limit and do not count toward it. There is no limit on the number of open pull requests for security updates."

The context of this note is within the open-pull-requests-limit section and as I've understood it, the first sentence is true. However, the second sentence seems to conflict with the TSG which calls out a hard limit of 10 open security update PRs.

My confusion - does this maximum for open security update PRs exist?

  • If yes, then the second sentence in the note should either be removed or tweaked to something like "The hard limit of 10 open PRs for security updates is not configurable using open-pull-requests-limit ."
  • If no and it doesn't exist, then probably the TSG reference should be fixed?

Additional information

No response

Activity

  1. added
    contentThis issue or pull request belongs to the Docs Content team
    on Sep 29, 2026
  2. welcome commented on Sep 29, 2026

    @welcome

    Thanks for opening this issue. A GitHub docs team member should be by to give feedback soon. In the meantime, please check out the contributing guidelines.

  3. added
    triageDo not begin working on this issue until triaged by the team
    on Sep 29, 2026
  4. subatoi commented on Sep 29, 2026

    @subatoi
    Contributor

    @FaithOmbongi thanks for raising this—you're correct that there's an apparent discrepancy and I'll mark it for the appropriate team to investigate, and follow up as soon as possible.

  5. added and removed
    triageDo not begin working on this issue until triaged by the team
    on Sep 29, 2026
  6. Jdub5007 commented on Oct 1, 2026

    @Jdub5007

    I went digging through the commit history on this, and I think the answer is
    that the TSG page is the stale one.

    So the note you quoted isn't an oversight, it's the correction. It replaced
    the exact claim the TSG still makes.

    The 10 was deliberately removed from the options reference on 2026-07-23
    in commit 10df0a2 ("Clarify docs about security updates open PR limits"):

    -* Security updates have a separate, internal limit of ten open pull requests which cannot be changed.
    +
    +> [!NOTE]
    +> _Security update_ pull requests are not subject to this limit and do not count toward it. There is no limit on the number of open pull requests for security updates.
    
    
    
  7. FaithOmbongi commented on Oct 1, 2026

    @FaithOmbongi
    ContributorAuthor

    Thanks for digging into the history @Jdub5007. I was unsure whether the limit had even existed previously or if the number was a doc error; also couldn't find a previous GitHub blog post regarding a change in limits - GH folks are pretty good at communicating such changes. And this sentence in this recent blog gives no indication about open PR limits.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    contentThis issue or pull request belongs to the Docs Content teamdriver personanever-staleDo not close as stale

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions