From 946cebdf9de7de91395aad4cb074413f98c9f833 Mon Sep 17 00:00:00 2001 From: Himanshucodess Date: Fri, 2 Oct 2026 11:53:35 +0530 Subject: [PATCH] Fix conflicting Dependabot security update PR limit (10, not unlimited) The open-pull-requests-limit reference claimed there is no limit on open security update PRs, contradicting the Dependabot errors TSG which documents a limit of 10 security update PRs (and 5 configurable version update PRs, with separate limits). Closes #46116 --- .../supply-chain-security/dependabot-options-reference.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/code-security/reference/supply-chain-security/dependabot-options-reference.md b/content/code-security/reference/supply-chain-security/dependabot-options-reference.md index b8ecf39c3ef4..b42e3e1c84ad 100644 --- a/content/code-security/reference/supply-chain-security/dependabot-options-reference.md +++ b/content/code-security/reference/supply-chain-security/dependabot-options-reference.md @@ -541,7 +541,7 @@ Change the limit on the maximum number of pull requests for version updates open * If five pull requests with version updates are open, no further pull requests are raised until some of those open requests are merged or closed. > [!NOTE] -> _Security update_ pull requests are not subject to this limit and do not count toward it. There is no limit on the number of open pull requests for security updates. +> _Security update_ pull requests are not subject to this limit and do not count toward it. There is a limit of 10 open pull requests for security updates, which is not configurable using `open-pull-requests-limit`. When `open-pull-requests-limit` is defined: