Dependabot 依赖更新配置
原名:dependabot
为 GitHub 仓库编写或审查 Dependabot 配置,控制依赖检查范围、频率和更新策略。
中文 Skills 技能说明
适合维护开源或企业项目依赖。先核对包管理器、分支和 CI 能力,避免一次生成大量不可验证更新;写入配置、开启服务或创建 PR 前需有仓库授权。
上游能力依据
上游原始适用说明:Comprehensive guide for configuring and managing GitHub Dependabot. Use this skill when users ask about creating or optimizing dependabot.yml files, managing Dependabot pull requests, configuring dependency update strategies, setting up grouped updates, monorepo patterns, multi-ecosystem groups, security update configuration, auto-triage rules, or any GitHub Advanced Security (GHAS) supply chain security topic related to Dependabot. For pre-commit dependency vulnerability scanning in AI coding agents via the GitHub MCP Server, this skill references the Advanced Security plugin (advanced-security@copilot-plugins). Use this skill when an agent needs to scan dependencies for known vulnerabilities before committing.
上游 SKILL.md 主要章节(保留原文标题):
- Overview
- Configuration Workflow
- Step 1: Detect All Ecosystems
- Step 2: Map Directory Locations
- Step 3: Configure Each Ecosystem Entry
- Step 4: Optimize with Grouping, Labels, and Scheduling
- Monorepo Strategies
- Glob Patterns for Workspace Coverage
- Cross-Directory Grouping
- Standalone Packages Outside Workspaces
使用边界
先核对运行环境、账号、区域、依赖和最小权限。创建资源、改配置、发布服务或产生费用前必须让使用者确认。
作者、翻译与许可证
- 原作者
- GitHub, Inc. 与 awesome-copilot contributors
- 中文翻译
- CEOFans翻译
- 许可证
- MIT
- 上游来源
- https://github.com/github/awesome-copilot/tree/3f0bba475ec40b9680e1d0311b9caffeec5ad4c3/skills/dependabot
适用范围
平台:linux、macos、windows;标签:开发运维、Dependabot 依赖更新配置
安全提示
基础静态扫描不等于绝对安全。技能可能调用命令、浏览器、云服务或本地文件,请在最小权限环境中使用,高风险操作必须人工确认。
如发现侵权、许可证或安全问题,可在本页前台提交投诉,管理员复核后可立即下架。