From 95d1d07792b9c551c6c2ec090450341eb01c3333 Mon Sep 17 00:00:00 2001 From: Ben Walding Date: Tue, 6 Oct 2026 10:15:01 +1000 Subject: [PATCH 1/2] Update ip-allow-lists-which-resources-are-protected.md Make the gap in enterprise IP restrictions clearer (this clarification also helps AI responses understand the security gap this creates). (I'd prefer that the IP restrictions were applied to forks too - but this will suffice for now). --- .../ip-allow-lists-which-resources-are-protected.md | 1 + 1 file changed, 1 insertion(+) diff --git a/data/reusables/identity-and-permissions/ip-allow-lists-which-resources-are-protected.md b/data/reusables/identity-and-permissions/ip-allow-lists-which-resources-are-protected.md index eab2f113a26c..d5c373d9d2d5 100644 --- a/data/reusables/identity-and-permissions/ip-allow-lists-which-resources-are-protected.md +++ b/data/reusables/identity-and-permissions/ip-allow-lists-which-resources-are-protected.md @@ -20,3 +20,4 @@ IP allow lists do **not** restrict access to: * A {% data variables.product.prodname_github_app %} (server-to-server) installation token when the {% data variables.product.prodname_github_app %} is installed on a user account. * {% data variables.product.prodname_copilot %} features that do not require directly fetching private or organizational data from {% data variables.product.prodname_dotcom %} * Anonymized URLs for images and videos uploaded to issues or pull requests, such as `https://private-user-images.githubusercontent.com/10001/20002.png?jwt=ABC10001`, unless you use {% data variables.enterprise.data_residency %} +* Repository forks owned by regular users (not {% data variables.enterprise.prodname_managed_users %}). From 978a66c6b3a1f55856bb6fb8cc4302a003b7b2bf Mon Sep 17 00:00:00 2001 From: Laura Coursen Date: Tue, 6 Oct 2026 12:06:13 -0500 Subject: [PATCH 2/2] Add :nail_care: --- .../ip-allow-lists-which-resources-are-protected.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/reusables/identity-and-permissions/ip-allow-lists-which-resources-are-protected.md b/data/reusables/identity-and-permissions/ip-allow-lists-which-resources-are-protected.md index d5c373d9d2d5..d6e4f1b3cf9a 100644 --- a/data/reusables/identity-and-permissions/ip-allow-lists-which-resources-are-protected.md +++ b/data/reusables/identity-and-permissions/ip-allow-lists-which-resources-are-protected.md @@ -20,4 +20,4 @@ IP allow lists do **not** restrict access to: * A {% data variables.product.prodname_github_app %} (server-to-server) installation token when the {% data variables.product.prodname_github_app %} is installed on a user account. * {% data variables.product.prodname_copilot %} features that do not require directly fetching private or organizational data from {% data variables.product.prodname_dotcom %} * Anonymized URLs for images and videos uploaded to issues or pull requests, such as `https://private-user-images.githubusercontent.com/10001/20002.png?jwt=ABC10001`, unless you use {% data variables.enterprise.data_residency %} -* Repository forks owned by regular users (not {% data variables.enterprise.prodname_managed_users %}). +* Repository forks owned by personal accounts (not {% data variables.enterprise.prodname_managed_users %})