如何在GitHub Actions中忽略Dependabot触发的Pull Request工作流
如何阻止Dependabot触发指定的GitHub Actions工作流?
我之前也碰到过一模一样的问题,你的核心需求很明确:保留Dependabot自动更新PR的功能,但让Pull Request工作流只在团队成员提交到staging分支的PR上触发,拒绝Dependabot的PR触发这个工作流。结合GitHub的最新规则,给你几个可行的解决方案:
最直接的修复:使用正确的Dependabot Actor名称
你之前尝试的方案2逻辑是对的,但问题出在Dependabot的标识上——现在官方的Dependabot机器人统一使用dependabot[bot]作为actor名称,而不是旧版的dependabot-preview[bot]。修改后的配置如下:
name: Pull Request on: pull_request: branches: - staging jobs: Build: # 排除Dependabot发起的PR if: github.actor != 'dependabot[bot]' name: Build runs-on: ubuntu-latest steps: - name: Check out code uses: actions/checkout@v2
更严谨的方案:检查PR的提交用户
有时候github.actor可能会因为手动触发等特殊场景出现偏差,你可以直接检查PR的提交用户,这个值会更稳定:
name: Pull Request on: pull_request: branches: - staging jobs: Build: # 通过PR的提交用户判断是否为Dependabot if: github.event.pull_request.user.login != 'dependabot[bot]' name: Build runs-on: ubuntu-latest steps: - name: Check out code uses: actions/checkout@v2
为什么你之前的尝试无效?
- 方案1逻辑错误:
branches字段里的!dependabot/**是用来过滤PR的目标分支,而不是源分支。Dependabot的PR目标分支是staging,所以这个排除规则根本不会生效。 - 方案2使用了过时的Actor名称:
dependabot-preview[bot]是旧版Dependabot的标识,现在官方已经弃用这个名称,所以你的条件判断等于没起作用。 - 尝试
depbot也无效:这个名称从来不是官方Dependabot的合法标识,自然无法匹配到目标机器人。
额外提示:双重保险的配置
如果你担心还有其他机器人触发工作流,可以同时排除多个actor,比如:
if: github.actor != 'dependabot[bot]' && github.actor != 'github-actions[bot]'
内容的提问来源于stack exchange,提问作者Amitb
相关产品推荐
相关产品推荐

