You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在GitHub Actions中忽略Dependabot触发的Pull Request工作流

如何阻止Dependabot触发指定的GitHub Actions工作流?

我之前也碰到过一模一样的问题,你的核心需求很明确:保留Dependabot自动更新PR的功能,但让Pull Request工作流只在团队成员提交到staging分支的PR上触发,拒绝Dependabot的PR触发这个工作流。结合GitHub的最新规则,给你几个可行的解决方案:

最直接的修复:使用正确的Dependabot Actor名称

你之前尝试的方案2逻辑是对的,但问题出在Dependabot的标识上——现在官方的Dependabot机器人统一使用dependabot[bot]作为actor名称,而不是旧版的dependabot-preview[bot]。修改后的配置如下:

name: Pull Request
on:
  pull_request:
    branches:
      - staging
jobs:
  Build:
    # 排除Dependabot发起的PR
    if: github.actor != 'dependabot[bot]'
    name: Build
    runs-on: ubuntu-latest
    steps:
      - name: Check out code
        uses: actions/checkout@v2

更严谨的方案:检查PR的提交用户

有时候github.actor可能会因为手动触发等特殊场景出现偏差,你可以直接检查PR的提交用户,这个值会更稳定:

name: Pull Request
on:
  pull_request:
    branches:
      - staging
jobs:
  Build:
    # 通过PR的提交用户判断是否为Dependabot
    if: github.event.pull_request.user.login != 'dependabot[bot]'
    name: Build
    runs-on: ubuntu-latest
    steps:
      - name: Check out code
        uses: actions/checkout@v2

为什么你之前的尝试无效?

  • 方案1逻辑错误:branches字段里的!dependabot/**是用来过滤PR的目标分支,而不是源分支。Dependabot的PR目标分支是staging,所以这个排除规则根本不会生效。
  • 方案2使用了过时的Actor名称:dependabot-preview[bot]是旧版Dependabot的标识,现在官方已经弃用这个名称,所以你的条件判断等于没起作用。
  • 尝试depbot也无效:这个名称从来不是官方Dependabot的合法标识,自然无法匹配到目标机器人。

额外提示:双重保险的配置

如果你担心还有其他机器人触发工作流,可以同时排除多个actor,比如:

if: github.actor != 'dependabot[bot]' && github.actor != 'github-actions[bot]'

内容的提问来源于stack exchange,提问作者Amitb

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 16:57:32