如何简化Dependabot自动合并PR工作流,避免主分支双提交?
问题
我用Dependabot+GitHub Actions自动合PR,工作流能正常跑,但每次合并到main分支后都会生成两个提交,想简化这个工作流。
当前配置文件:
.github/dependabot.yml
version: 2 updates: - package-ecosystem: "nuget" directory: "/src" schedule: interval: "daily" labels: - "automerge" - "dependencies" # Configuration for npm - package-ecosystem: "npm" directory: "/src" schedule: interval: "daily" labels: - "automerge" - "dependencies"
.github/workflows/auto-merge-dependabot.yml
name: Dependabot auto-merge on: pull_request: types: - opened - labeled - synchronize permissions: contents: write pull-requests: write jobs: dependabot: runs-on: ubuntu-latest if: github.actor == 'dependabot[bot]' steps: - name: Dependabot metadata id: metadata uses: dependabot/fetch-metadata@v2 with: github-token: "${{ secrets.GITHUB_TOKEN }}" - name: Verify Dependabot run: | if [[ "${{ github.event.sender.type }}" != "Bot" || "${{ github.event.sender.login }}" != "dependabot[bot]" ]]; then echo "This PR is not from Dependabot." exit 1 fi - name: Enable auto-merge for Dependabot PRs if: contains(github.event.pull_request.labels.*.name, 'automerge') run: gh pr merge --auto --merge "$PR_URL" env: PR_URL: ${{github.event.pull_request.html_url}} GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
原因分析
- 双提交问题:当前用的
gh pr merge --auto --merge是默认合并方式,会保留Dependabot生成的单独提交,再新增一条"Merge pull request #XXX..."的合并提交,所以最终出现两个提交。 - 工作流冗余:自定义Actions里的元数据获取、Bot验证步骤都是多余的,GitHub原生支持Dependabot自动合并,没必要额外写这些逻辑。
解决方案
方案1:用GitHub原生自动合并(推荐,彻底简化)
直接在Dependabot配置里开启自动合并,指定合并策略为压缩提交,无需保留自定义Actions工作流。
步骤1:修改.github/dependabot.yml
添加自动合并和压缩提交的配置:
version: 2 updates: - package-ecosystem: "nuget" directory: "/src" schedule: interval: "daily" labels: - "automerge" - "dependencies" # 配置自动合并规则,这里允许所有类型依赖的补丁版本更新自动合并 automerged_updates: - match: dependency_type: "all" update_type: "semver:patch" # 合并时压缩PR提交为单个提交,避免双提交 merge-strategy: squash: true # npm配置同理 - package-ecosystem: "npm" directory: "/src" schedule: interval: "daily" labels: - "automerge" - "dependencies" automerged_updates: - match: dependency_type: "all" update_type: "semver:patch" merge-strategy: squash: true
- 若想允许小版本甚至大版本更新自动合并,可把
update_type改成semver:minor或all。 - 偏好线性提交历史的话,可把
squash: true换成rebase: true,效果一样都是单提交。
步骤2:删除多余的Actions工作流
直接删掉.github/workflows/auto-merge-dependabot.yml,Dependabot会自动处理合并流程。
方案2:调整现有Actions工作流(保留自定义脚本的话用这个)
如果不想删现有Actions,只需修改合并命令的参数,同时删掉冗余步骤:
修改后的.github/workflows/auto-merge-dependabot.yml
name: Dependabot auto-merge on: pull_request: types: - opened - labeled - synchronize permissions: contents: write pull-requests: write jobs: dependabot: runs-on: ubuntu-latest # 直接把判断条件写在job层面,省去步骤里的验证 if: github.actor == 'dependabot[bot]' && contains(github.event.pull_request.labels.*.name, 'automerge') steps: - name: Auto-merge Dependabot PRs # 用--squash替代原有的--merge,压缩提交为单个 run: gh pr merge --auto --squash "$PR_URL" env: PR_URL: ${{github.event.pull_request.html_url}} GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- 同样,可用
--rebase替换--squash,根据提交历史偏好选择。
内容的提问来源于stack exchange,提问作者Richard
相关产品推荐
相关产品推荐

