能否通过Dependabot YAML配置文件添加选项禁用该工具?
关于Dependabot配置文件中禁用选项的问题
不能通过在Dependabot YAML配置文件里添加选项来全局禁用Dependabot,官方确实没把全局禁用作为配置项放在这个文件里。如果要停止Dependabot运行,有几种可行的办法:
- 直接删除仓库中的
.github/dependabot.yml配置文件,Dependabot会自动停止对该仓库的扫描和更新操作。 - 手动在仓库设置中关闭:进入仓库的「Settings」页面,找到「Code security and analysis」板块,分别关闭「Dependabot alerts」和「Dependabot security updates」的开关。
- 如果只是想禁用某一类依赖生态系统的更新(而非全局禁用),可以在配置文件中给对应生态系统的配置块加上
enabled: false参数,比如:
version: 2 updates: # 禁用npm依赖更新 - package-ecosystem: "npm" directory: "/" schedule: interval: "daily" enabled: false # 保留GitHub Actions的更新配置 - package-ecosystem: "github-actions" directory: "/" schedule: interval: "weekly"
内容的提问来源于stack exchange,提问作者David Walz
相关产品推荐
相关产品推荐

