Dependabot PR自动推送Slack的Workflow仅手动生效问题求助
问题解决:Dependabot PR的Slack通知不触发
问题描述
我写了一个GitHub Workflow,想要实现:
- Dependabot创建漏洞/依赖更新PR时,推送到Slack频道,附带PR链接
- PR合并后,更新Slack里的原消息
现在的情况是:
- 手动触发Workflow正常(但没有自动生成的PR链接)
- Dependabot自动创建PR时,Slack完全没推送
- 已经在仓库密钥和Dependabot专属密钥里加了所需Secret,试过
if: ${{ github.actor == 'dependabot[bot]' }}这类配置,但参考资料大多用旧版Action,解决不了当前问题
原Workflow代码:
name: Dependabot PR Notification to Slack on: pull_request_target: types: [opened, reopened] branches: - 'dependabot/**' workflow_dispatch: permissions: pull-requests: write actions: write repository-projects: write jobs: Slack-PR-Notification: name: Slack PR Notification runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v4 - name: Slack Notification uses: slackapi/slack-github-action@v1.25.0 id: slack with: payload: | { "text": "New ${{ github.repository}} Dependabot PR Available for Review: ${{ github.event.pull_request.html_url}}" } env: SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }} SLACK_WEBHOOK_TYPE: INCOMING_WEBHOOK - uses: slackapi/slack-github-action@v1.25.0 if: ${{ github.event.pull_request.merged }} with: update-ts: ${{ steps.slack.outputs.ts }} payload: | { "text": "PR has been merged. Thank you!", "attachments": [ { "pretext": "Merge complete", "color": "28a745", "fields": [ { "title": "Status", "short": true, "value": "Completed" } ] } ] } env: SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }} SLACK_WEBHOOK_TYPE: INCOMING_WEBHOOK
核心问题分析
- 触发条件的分支过滤错误:
pull_request_target的branches字段过滤的是PR的目标分支,而Dependabot的PR是从dependabot/**分支合并到你的主分支(比如main),所以原配置里的branches: ['dependabot/**']会导致只有目标分支是dependabot开头的PR才触发,这完全不符合需求,直接导致Dependabot的PR无法触发Workflow。 - 合并事件未正确监听:原配置只监听了
opened和reopened类型,PR合并时触发的是closed类型,且需要判断是否是合并关闭,所以原步骤里的if: ${{ github.event.pull_request.merged }}永远不会触发,因为当前Workflow根本没监听合并事件。 - Slack消息TS无法跨Workflow共享:原代码里用
steps.slack.outputs.ts来更新消息,但PR合并时是另一次Workflow运行,这个TS值已经不存在,必须把TS存储到PR的持久化位置(比如PR评论)才能在合并时读取。
修复后的Workflow代码
name: Dependabot PR Notification to Slack on: pull_request_target: types: [opened, reopened, closed] # 这里改成你的PR目标分支,比如main、develop,或者去掉这行监听所有分支的PR branches: - main workflow_dispatch: permissions: pull-requests: write actions: write jobs: Slack-PR-Notification: name: Slack PR Notification runs-on: ubuntu-latest # 只处理Dependabot的PR if: ${{ github.actor == 'dependabot[bot]' }} steps: # 不需要checkout代码,因为没用到仓库内容 # - name: Checkout code # uses: actions/checkout@v4 # 步骤1:PR打开/重新打开时发送Slack消息,并把TS保存到PR评论 - name: Send Slack Notification for New PR if: ${{ github.event.action == 'opened' || github.event.action == 'reopened' }} id: slack-notify uses: slackapi/slack-github-action@v1.25.0 with: payload: | { "text": "New *${{ github.repository}}* Dependabot PR Available for Review: <${{ github.event.pull_request.html_url}}|#${{ github.event.pull_request.number }} - ${{ github.event.pull_request.title }}>" } env: SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }} SLACK_WEBHOOK_TYPE: INCOMING_WEBHOOK - name: Save Slack Message TS to PR Comment if: ${{ github.event.action == 'opened' || github.event.action == 'reopened' }} uses: actions/github-script@v7 with: script: | github.rest.issues.createComment({ issue_number: context.issue.number, owner: context.repo.owner, repo: context.repo.repo, body: `Slack message TS: ${{ steps.slack-notify.outputs.ts }}` }) # 步骤2:PR合并时,从PR评论读取TS并更新Slack消息 - name: Get Slack Message TS from PR Comments if: ${{ github.event.action == 'closed' && github.event.pull_request.merged }} id: get-slack-ts uses: actions/github-script@v7 with: script: | const comments = await github.rest.issues.listComments({ issue_number: context.issue.number, owner: context.repo.owner, repo: context.repo.repo, }) const tsComment = comments.data.find(comment => comment.body.startsWith('Slack message TS:')) if (tsComment) { const ts = tsComment.body.split(': ')[1].trim() core.setOutput('ts', ts) } else { core.setFailed('Slack message TS not found in PR comments') } - name: Update Slack Message for Merged PR if: ${{ github.event.action == 'closed' && github.event.pull_request.merged }} uses: slackapi/slack-github-action@v1.25.0 with: update-ts: ${{ steps.get-slack-ts.outputs.ts }} payload: | { "text": "PR *#${{ github.event.pull_request.number }} - ${{ github.event.pull_request.title }}* has been merged. Thank you!", "attachments": [ { "pretext": "Merge complete", "color": "28a745", "fields": [ { "title": "Status", "short": true, "value": "Completed" } ] } ] } env: SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }} SLACK_WEBHOOK_TYPE: INCOMING_WEBHOOK
关键修复点说明
- 修正触发条件:把
branches改成你的PR目标分支(比如main),并添加closed类型监听合并事件;用if: ${{ github.actor == 'dependabot[bot]' }}限定只处理Dependabot的PR。 - 移除无用的Checkout步骤:整个Workflow不需要读取仓库代码,所以可以删掉
actions/checkout。 - 持久化Slack消息TS:发送消息后把TS写入PR评论,合并时从评论里读取TS,解决跨Workflow的TS共享问题。
- 优化Slack消息格式:用Slack的链接格式
<URL|显示文本>让消息更易读,添加PR编号和标题。
内容的提问来源于stack exchange,提问作者Ashton Becher
相关产品推荐
相关产品推荐

