2.7.15 与 Dependabot 配合使用

原文链接: https://docs.astral.sh/uv/guides/integration/dependabot/

2.7.15 与 Dependabot 配合使用

定期更新依赖被认为是最佳实践,可以避免暴露于漏洞、减少依赖之间的不兼容,并避免因版本过旧而导致的复杂升级。

Dependabot 已宣布支持 uv,但还有一些用例尚不可用。更新情况请参阅 astral-sh/uv#2512。

Dependabot 支持更新 uv.lock 文件。要启用该功能,请在 dependabot.yml 的 updates 列表中加入 uv 的 package-ecosystem:

1
2
3
4
5
6
7
8
# dependabot.yml
version: 2

updates:
  - package-ecosystem: "uv"
    directory: "/"
    schedule:
      interval: "weekly"

依赖冷却期

如果你使用了 exclude-newer 选项,建议在 Dependabot 中也设置等价的 cooldown 选项,以免出现 uv 无法锁定依赖的拉取请求。

例如,如果你把 exclude-newer 设置为 1 week,可以这样设置:

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
# dependabot.yml
version: 2

updates:
  - package-ecosystem: "uv"
    directory: "/"
    schedule:
      interval: "weekly"
    cooldown:
      default-days: 7
最后修改 September 25, 2026: 更新 (221c74c33)