You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何简化Dependabot自动合并PR工作流,避免主分支双提交?

问题

我用Dependabot+GitHub Actions自动合PR,工作流能正常跑,但每次合并到main分支后都会生成两个提交,想简化这个工作流。

当前配置文件:

.github/dependabot.yml

version: 2
updates:
  - package-ecosystem: "nuget"
    directory: "/src"
    schedule:
      interval: "daily"
    labels:
      - "automerge"
      - "dependencies"

  # Configuration for npm
  - package-ecosystem: "npm"
    directory: "/src"
    schedule:
      interval: "daily"
    labels:
      - "automerge"
      - "dependencies"

.github/workflows/auto-merge-dependabot.yml

name: Dependabot auto-merge

on:
  pull_request:
    types:
      - opened
      - labeled
      - synchronize

permissions:
  contents: write
  pull-requests: write

jobs:
  dependabot:
    runs-on: ubuntu-latest
    if: github.actor == 'dependabot[bot]'
    steps:
      - name: Dependabot metadata
        id: metadata
        uses: dependabot/fetch-metadata@v2
        with:
          github-token: "${{ secrets.GITHUB_TOKEN }}"

      - name: Verify Dependabot
        run: |
          if [[ "${{ github.event.sender.type }}" != "Bot" || "${{ github.event.sender.login }}" != "dependabot[bot]" ]]; then
            echo "This PR is not from Dependabot."
            exit 1
          fi

      - name: Enable auto-merge for Dependabot PRs
        if: contains(github.event.pull_request.labels.*.name, 'automerge')
        run: gh pr merge --auto --merge "$PR_URL"
        env:
          PR_URL: ${{github.event.pull_request.html_url}}
          GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}

原因分析
  1. 双提交问题:当前用的gh pr merge --auto --merge是默认合并方式,会保留Dependabot生成的单独提交,再新增一条"Merge pull request #XXX..."的合并提交,所以最终出现两个提交。
  2. 工作流冗余:自定义Actions里的元数据获取、Bot验证步骤都是多余的,GitHub原生支持Dependabot自动合并,没必要额外写这些逻辑。

解决方案

方案1:用GitHub原生自动合并(推荐,彻底简化)

直接在Dependabot配置里开启自动合并,指定合并策略为压缩提交,无需保留自定义Actions工作流。

步骤1:修改.github/dependabot.yml

添加自动合并和压缩提交的配置:

version: 2
updates:
  - package-ecosystem: "nuget"
    directory: "/src"
    schedule:
      interval: "daily"
    labels:
      - "automerge"
      - "dependencies"
    # 配置自动合并规则,这里允许所有类型依赖的补丁版本更新自动合并
    automerged_updates:
      - match:
          dependency_type: "all"
          update_type: "semver:patch"
    # 合并时压缩PR提交为单个提交,避免双提交
    merge-strategy:
      squash: true

  # npm配置同理
  - package-ecosystem: "npm"
    directory: "/src"
    schedule:
      interval: "daily"
    labels:
      - "automerge"
      - "dependencies"
    automerged_updates:
      - match:
          dependency_type: "all"
          update_type: "semver:patch"
    merge-strategy:
      squash: true
  • 若想允许小版本甚至大版本更新自动合并,可把update_type改成semver:minor或all。
  • 偏好线性提交历史的话,可把squash: true换成rebase: true,效果一样都是单提交。

步骤2:删除多余的Actions工作流

直接删掉.github/workflows/auto-merge-dependabot.yml,Dependabot会自动处理合并流程。


方案2:调整现有Actions工作流(保留自定义脚本的话用这个)

如果不想删现有Actions,只需修改合并命令的参数,同时删掉冗余步骤:

修改后的.github/workflows/auto-merge-dependabot.yml

name: Dependabot auto-merge

on:
  pull_request:
    types:
      - opened
      - labeled
      - synchronize

permissions:
  contents: write
  pull-requests: write

jobs:
  dependabot:
    runs-on: ubuntu-latest
    # 直接把判断条件写在job层面,省去步骤里的验证
    if: github.actor == 'dependabot[bot]' && contains(github.event.pull_request.labels.*.name, 'automerge')
    steps:
      - name: Auto-merge Dependabot PRs
        # 用--squash替代原有的--merge,压缩提交为单个
        run: gh pr merge --auto --squash "$PR_URL"
        env:
          PR_URL: ${{github.event.pull_request.html_url}}
          GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  • 同样,可用--rebase替换--squash,根据提交历史偏好选择。

内容的提问来源于stack exchange,提问作者Richard

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 20:13:15