用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/G1Joshi/Agent-Skills --skill dependabot命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | dependabot |
| description | Dependabot dependency updates. Use for security updates. |
Dependabot creates pull requests to keep your dependencies secure and up-to-date. It is integrated natively into GitHub.
dependabot.yml)# .github/dependabot.yml
version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
# Grouping (2025 feature) reduces noise
groups:
dependencies:
patterns:
- "*"
Triggered automatically when GitHub detects a vulnerability in your dependencies (via Dependency Graph). These are distinct from Version Updates.
Scheduled updates (Daily/Weekly) to newer versions, regardless of vulnerabilities. Driven by dependabot.yml.
Combining multiple package updates into a single PR (e.g., "Bump 5 dependencies"). Drastically reduces PR noise.
Do:
Don't:
| Error | Cause | Solution |
|---|---|---|
No PRs created | Config error or no updates needed. | Check "Dependabot" tab in Insights -> Dependency Graph. |
Merge Conflicts | Lockfile out of sync. | Rebase the PR (@dependabot rebase). |