Based on this PR comment: #77 (comment)
Since the step that fails is non-critical (uploading dependency metadata to Dependabot) we could either allow external devs to trigger it or we could make it optional (since it will be run in the master branch build after merge).
Seems to be by design...
The best solution now is probably to make this step optional.