Dependabot docs disagree on when the ecosystem label is added, and on its name (github-actions vs github_actions)
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 1/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 83/100
- Issue 类型
- 文档
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
调研方向
阅读选项参考中关于 Dependabot 默认行为的部分,以及提供自定义文章文本的 data/reusables/dependabot/default-labels.md。统一两篇文章中的生态系统标签规则,并将 GitHub Actions 示例改为 github_actions。当两处描述一致且示例与报告的标签名称相符时,即为完成。
由索引模型根据 Issue 内容生成。
描述
Code of Conduct
- I have read and agree to the GitHub Docs project's Code of Conduct
What article on docs.github.com is affected?
- https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#labels--
- https://docs.github.com/en/code-security/tutorials/secure-your-dependencies/customizing-dependabot-prs (its default-labels text comes from
data/reusables/dependabot/default-labels.md)
What part(s) of the article would you like to see updated?
The two articles describe Dependabot's default labels in ways that contradict each other:
-
When the ecosystem label is added. The options reference (
labels→ "Dependabot default behavior") says the ecosystem label is added only when more than one package manager is defined. The customizing article (thedefault-labelsreusable) says both thedependencieslabel and the ecosystem label are added to all pull requests, single-ecosystem updates included. Both can't be right; the observed behavior matches the second (see below). -
The name of the GitHub Actions ecosystem label. The reusable uses
github-actionsas an example, but the label Dependabot actually creates and applies isgithub_actions, with an underscore.
Expected outcome: both articles state the same rule for the ecosystem label, and the GitHub Actions example uses the label name Dependabot really applies.
Additional information
Reproduced in a private repository whose dependabot.yml has a single entry (package-ecosystem: github-actions, no labels option) and that had neither label beforehand. Dependabot's first version-update pull request created both labels and applied them: the pull request's events show dependabot[bot] adding dependencies and github_actions. The github_actions label it created had the description "Pull requests that update GitHub Actions code".
- 主要语言
- TypeScript
- 星标
- 21k
- 派生
- 69k
- 平均合并
- 8 小时 37 分钟
- 30 天内合并 PR
- 117
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 提供 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
github/docs 的其他 Issue
-
content triage
难度 2/5 1-3 小时 新手友好度 74/100
维护者通常 1 天内回复
-
content driver persona triage
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 1 天内回复
-
triage
难度 2/5 1-3 小时 新手友好度 75/100
维护者通常 1 天内回复
-
builder persona content
难度 2/5 1-3 小时 新手友好度 76/100
维护者通常 1 天内回复
-
Add user-level custom agent configuration可能已有人在做 @ashis-baral 于 7 天前认领。 未关闭builder persona content copilot
难度 1/5 1 小时以内 新手友好度 90/100
维护者通常 1 天内回复
相似的 Issue
-
难度 1/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
core
难度 2/5 1-3 小时 新手友好度 70/100
vectorize-io/hindsight#5457 ·
维护者通常 1 天内回复
-
beginner friendly community contributions-welcome good first issue hacktoberfest help wanted testing up-for-grabs
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 85/100
lukilabs/beautiful-mermaid#160 ·
-
难度 2/5 1-3 小时 新手友好度 66/100
rescript-lang/rescript-lang.org#1420 ·
维护者通常 2 天内回复