如何配置Dependabot以使用ProGet私有包源?
让Dependabot识别ProGet私有NuGet源的方法
Dependabot不会自动读取项目里的NuGet源配置(比如NuGet.Config),必须在它的配置文件里显式指定私有注册表。
具体配置步骤:
- 在仓库的
.github/dependabot.yml文件中,添加全局的registries块定义你的ProGet源,同时在nuget生态系统的更新规则里关联这个注册表。 - 示例配置:
version: 2 updates: - package-ecosystem: "nuget" directory: "/" schedule: interval: "daily" registries: - proget-private-feed # 关联下面的私有源 registries: proget-private-feed: type: nuget-feed url: "https://你的ProGet实例地址/nuget/你的Feed名称/" # 若ProGet需要认证,用GitHub Secrets存储凭证(不能明文写) username: "${{ secrets.PROGET_USER }}" password: "${{ secrets.PROGET_PWD }}"
关键注意点:
- 认证信息一定要存在GitHub Secrets中,避免泄露敏感信息。
- 必须在
updates块的registries列表里包含你的ProGet源,这样Dependabot才会同时检索官方NuGet源和私有源的依赖更新。 - 如果ProGet源是公开的,直接去掉
username和password字段即可。
内容的提问来源于stack exchange,提问作者onesixtyfourth
相关产品推荐
相关产品推荐

