Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Automate dependency updates with a scheduled Action

Đang mở Phù hợp với người mới
#21,640 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
Nửa ngày
Mức phù hợp với người mới
68/100
Loại issue
Tính năng
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
github-actions
Lĩnh vực
ci-cd

Hướng nghiên cứu

Bắt đầu bằng việc xem xét các workflow GitHub Actions hiện có và các manifest dependency của repository, sau đó so sánh các quyền và trigger kiểm thử của chúng với workflow theo lịch được đề xuất. Công việc được xem là hoàn tất khi một workflow chạy hằng tháng sử dụng chiến lược non-breaking được chỉ định và release age 14 ngày, tạo các pull request cập nhật, đồng thời maintainer đã xác nhận cấu hình PAT bắt buộc.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

enhancement triaged
🚀 The feature, motivation and pitch

Hi, thanks for creating and maintaining this package. I use it in some of my own projects and wanted to help make sure it stays secure and well maintained with the least effort from maintainers.

Looking through the commit history, dependency bumps look like they're done manually right now, but I've recently created a new GitHub Action called Update Dependencies that might help here: https://github.com/marketplace/actions/update-dependencies

It scans your package manager(s), opens a PR with version bumps, and labels each change as breaking or non-breaking (Depending on which strategy we use).

Suggested setup for this repo:

  • Run it monthly, non-breaking updates only, so not much manual review is needed.
  • Set min-release-age-days to 14 (default is 3, similar to Github's Dependabot). That gives the community about two weeks to catch bugs or security issues in a new release before it lands here.
  • If you already run tests on every PR (which it seems you do), no extra config needed; your CI just checks the update PR like any other PR.

One thing worth noting: the GitHub token should be a PAT rather than the default token, so your CI actually triggers on the PR it opens. That'd need an admin to create and maintain.

Example workflow:

name: Update Dependencies

on:
  schedule:
    - cron: '0 2 1 * *' # monthly, 1st of month at 02:00 UTC
  workflow_dispatch:

permissions:
  contents: write
  pull-requests: write

jobs:
  update:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: yanovian/update-dependencies-action@v1
        with:
          update-strategy: non-breaking
          min-release-age-days: 14
          create-pull-request: true
          github-token: ${{ secrets.PAT_TOKEN }}

What do you think? Happy to help set it up if useful.

Alternatives

Manual update or "custom scripts" but none of them actually check with the list of CVEs, and also it is not easy to check the update time for every single package.

Additional context

No response

RFC (Optional)

No response

Ngôn ngữ chính
Python
Star
5k
Fork
1.2k
Merge trung bình
2 ngày 12 giờ
Pull request đã merge (30 ngày)
588

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của pytorch/executorch

Tất cả issue của pytorch/executorch

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.