如何让Dependabot更新复合Action中依赖的GitHub Actions?
问题:Dependabot无法自动更新自定义复合Action中的依赖
我有一个托管共享GitHub Actions逻辑的仓库,文件结构如下:
.github |_ workflows |_ shared-workflow-1 |_ ... |_ shared-workflow-2 |_ ... |_ custom-action-1 |_ action.yaml |_ custom-action-2 |_ action.yaml
注:受GitHub限制,Workflow必须放在.github/workflows目录下,自定义Action可放在仓库根目录,通过my-github-logic-repo@custom-action1@main调用。我的custom-action-*是复合Action,依赖GitHub Marketplace中的Action,希望通过Dependabot自动更新这些依赖。
我已配置.github/dependabot.yml如下:
version: 2 updates: - package-ecosystem: "github-actions" directory: "/" schedule: interval: "weekly"
但Dependabot仅针对Workflow中的Action创建更新PR,完全忽略自定义复合Action中的依赖。请问是否有办法让Dependabot检查自定义Action的更新,或者目前暂不支持该功能?
回答
目前Dependabot的github-actions生态系统默认只会扫描.github/workflows目录下的Workflow文件,不会自动遍历仓库中其他目录的复合Action配置文件。不过可以通过调整Dependabot配置来实现对自定义复合Action的依赖扫描:
解决方案:为每个自定义Action目录添加单独的更新规则
修改你的.github/dependabot.yml,为每个自定义Action的目录单独配置扫描规则,指定对应的directory路径:
version: 2 updates: # 扫描workflows目录中的Action依赖 - package-ecosystem: "github-actions" directory: "/.github/workflows" schedule: interval: "weekly" # 扫描custom-action-1目录下的复合Action依赖 - package-ecosystem: "github-actions" directory: "/custom-action-1" schedule: interval: "weekly" # 扫描custom-action-2目录下的复合Action依赖 - package-ecosystem: "github-actions" directory: "/custom-action-2" schedule: interval: "weekly"
关键说明
- 每个自定义Action的目录下必须存在
action.yaml(或action.yml)文件,Dependabot会识别该文件中的uses字段,检测其中引用的GitHub Action依赖版本。 - 若后续新增自定义Action,需要在
dependabot.yml中添加对应的目录扫描条目,才能让Dependabot自动处理新的依赖更新。
内容的提问来源于stack exchange,提问作者cmousset
相关产品推荐
相关产品推荐

