配置Dependabot工作流多npm镜像源时解析报错,求排查问题
解决Dependabot多npm源配置的Schema错误
错误原因是你手动定义了npmjs registry条目,Dependabot默认已经内置对registry.npmjs.org的支持,无需在registries块中重复声明,手动添加该条目会触发Schema校验失败。
修正后的配置如下:
version: 2 registries: npm-github: type: npm-registry url: https://npm.pkg.github.com token: ${{ secrets.NPM_TOKEN }} updates: - package-ecosystem: github-actions directory: / schedule: interval: daily - package-ecosystem: npm registries: - npm-github directory: / schedule: interval: daily open-pull-requests-limit: 10
说明:
- 移除不必要的
npmjsregistry定义,Dependabot会自动使用官方npm源处理公共依赖 - 保留
npm-githubregistry配置,用于拉取你发布在GitHub Packages的私有包 - npm更新任务中指定
npm-githubregistry后,Dependabot会同时从默认源和私有源扫描依赖更新
内容的提问来源于stack exchange,提问作者Remi Sture
相关产品推荐
相关产品推荐

