如何阻止Dependabot创建补丁/热修复PR?仅允许次要版本更新
解决Azure DevOps中Dependabot仍生成补丁版本PR的问题
你的配置未生效的核心原因是:Dependabot在处理Maven生态的部分依赖(比如Spring Boot Parent)时,版本类型的识别逻辑可能与预期存在偏差,仅通过allow规则允许主次版本更新,无法完全过滤掉补丁版本的PR。
修正后的配置方案
你需要在原有配置基础上添加ignore块,明确排除所有补丁版本的更新,确保优先级覆盖allow规则:
version: 2 updates: - package-ecosystem: "maven" directory: "/" schedule: interval: "daily" target-branch: "develop" allow: - dependency-type: "direct" update-types: - "major" - "minor" ignore: - dependency-name: "*" update-types: ["patch"]
更精准的过滤(可选)
如果你只想针对Spring Boot的补丁更新进行忽略,可将ignore块改为:
ignore: - dependency-name: "org.springframework.boot:*" update-types: ["patch"]
额外检查点
- 确认你的配置文件中没有其他
updates块,避免多规则冲突 - 确保Azure DevOps已正确读取最新的
dependabot.yaml配置(可重新触发Dependabot扫描验证)
内容的提问来源于stack exchange,提问作者Pitto
相关产品推荐
相关产品推荐

