You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何阻止Dependabot创建补丁/热修复PR?仅允许次要版本更新

解决Azure DevOps中Dependabot仍生成补丁版本PR的问题

你的配置未生效的核心原因是:Dependabot在处理Maven生态的部分依赖(比如Spring Boot Parent)时,版本类型的识别逻辑可能与预期存在偏差,仅通过allow规则允许主次版本更新,无法完全过滤掉补丁版本的PR。

修正后的配置方案

你需要在原有配置基础上添加ignore块,明确排除所有补丁版本的更新,确保优先级覆盖allow规则:

version: 2
updates:
  - package-ecosystem: "maven"
    directory: "/"
    schedule:
      interval: "daily"
    target-branch: "develop"
    allow:
      - dependency-type: "direct"
        update-types:
          - "major"
          - "minor"
    ignore:
      - dependency-name: "*"
        update-types: ["patch"]

更精准的过滤(可选)

如果你只想针对Spring Boot的补丁更新进行忽略,可将ignore块改为:

ignore:
  - dependency-name: "org.springframework.boot:*"
    update-types: ["patch"]

额外检查点

  • 确认你的配置文件中没有其他updates块,避免多规则冲突
  • 确保Azure DevOps已正确读取最新的dependabot.yaml配置(可重新触发Dependabot扫描验证)

内容的提问来源于stack exchange,提问作者Pitto

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 22:45:09