You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让Dependabot更新复合Action中依赖的GitHub Actions?

问题:Dependabot无法自动更新自定义复合Action中的依赖

我有一个托管共享GitHub Actions逻辑的仓库,文件结构如下:

.github
|_ workflows
  |_ shared-workflow-1
     |_ ...
  |_ shared-workflow-2
     |_ ...
|_ custom-action-1
     |_ action.yaml
|_ custom-action-2
     |_ action.yaml

注:受GitHub限制,Workflow必须放在.github/workflows目录下,自定义Action可放在仓库根目录,通过my-github-logic-repo@custom-action1@main调用。我的custom-action-*是复合Action,依赖GitHub Marketplace中的Action,希望通过Dependabot自动更新这些依赖。

我已配置.github/dependabot.yml如下:

version: 2

updates:
  - package-ecosystem: "github-actions"
    directory: "/"
    schedule:
      interval: "weekly"

但Dependabot仅针对Workflow中的Action创建更新PR,完全忽略自定义复合Action中的依赖。请问是否有办法让Dependabot检查自定义Action的更新,或者目前暂不支持该功能?


回答

目前Dependabot的github-actions生态系统默认只会扫描.github/workflows目录下的Workflow文件,不会自动遍历仓库中其他目录的复合Action配置文件。不过可以通过调整Dependabot配置来实现对自定义复合Action的依赖扫描:

解决方案:为每个自定义Action目录添加单独的更新规则

修改你的.github/dependabot.yml,为每个自定义Action的目录单独配置扫描规则,指定对应的directory路径:

version: 2
updates:
  # 扫描workflows目录中的Action依赖
  - package-ecosystem: "github-actions"
    directory: "/.github/workflows"
    schedule:
      interval: "weekly"
  # 扫描custom-action-1目录下的复合Action依赖
  - package-ecosystem: "github-actions"
    directory: "/custom-action-1"
    schedule:
      interval: "weekly"
  # 扫描custom-action-2目录下的复合Action依赖
  - package-ecosystem: "github-actions"
    directory: "/custom-action-2"
    schedule:
      interval: "weekly"

关键说明

  • 每个自定义Action的目录下必须存在action.yaml(或action.yml)文件,Dependabot会识别该文件中的uses字段,检测其中引用的GitHub Action依赖版本。
  • 若后续新增自定义Action,需要在dependabot.yml中添加对应的目录扫描条目,才能让Dependabot自动处理新的依赖更新。

内容的提问来源于stack exchange,提问作者cmousset

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 16:20:22