# Dependabot 快速入门指南

查找并修复您所依赖的 Dependabot 易受攻击的依赖项。

## 关于 Dependabot

本快速入门指南指导你完成设置和启用 Dependabot、查看 Dependabot alerts和更新存储库以使用依赖项的安全版本。

Dependabot 由三种不同的功能组成，可帮助你管理依赖项：

* Dependabot alerts：就存储库中使用的依赖项中的漏洞问题通知你。
* Dependabot security updates：自动引发拉取请求，以更新你使用的具有已知安全漏洞的依赖项。
* Dependabot version updates：自动引发拉取请求以使依赖项保持最新。

## 先决条件

在本指南中，我们将使用一个演示存储库来演示Dependabot如何查找依赖项中的漏洞、在Dependabot alertsGitHub中查看漏洞，以及如何浏览、修复或忽略这些警报。

首先需要创建演示存储库的分支。

1. 导航到 [https://github.com/dependabot/demo](https://github.com/dependabot/demo?ref_product=supply-chain-security\&ref_type=engagement\&ref_style=text)。
2. 在页面顶部右侧，单击 **<svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-repo-forked" aria-label="repo-forked" role="img"><path d="M5 5.372v.878c0 .414.336.75.75.75h4.5a.75.75 0 0 0 .75-.75v-.878a2.25 2.25 0 1 1 1.5 0v.878a2.25 2.25 0 0 1-2.25 2.25h-1.5v2.128a2.251 2.251 0 1 1-1.5 0V8.5h-1.5A2.25 2.25 0 0 1 3.5 6.25v-.878a2.25 2.25 0 1 1 1.5 0ZM5 3.25a.75.75 0 1 0-1.5 0 .75.75 0 0 0 1.5 0Zm6.75.75a.75.75 0 1 0 0-1.5.75.75 0 0 0 0 1.5Zm-3 8.75a.75.75 0 1 0-1.5 0 .75.75 0 0 0 1.5 0Z"></path></svg> 分支**。
3. 选择所有者（可以选择个人 GitHub 帐户），然后键入存储库名称。 有关派生存储库的详细信息，请参阅 [为存储库创建分支](/zh/enterprise-cloud@latest/pull-requests/collaborating-with-pull-requests/working-with-forks/fork-a-repo#forking-a-repository)。
4. 单击“创建分支”\*\*\*\*。

## 为你的存储库启用 Dependabot

你需要在[先决条件](#prerequisites)中分支的存储库上执行以下步骤。

1. 在 GitHub 上，导航到存储库的主页面。
2. 在仓库名称下，单击 <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-gear" aria-label="gear" role="img"><path d="M8 0a8.2 8.2 0 0 1 .701.031C9.444.095 9.99.645 10.16 1.29l.288 1.107c.018.066.079.158.212.224.231.114.454.243.668.386.123.082.233.09.299.071l1.103-.303c.644-.176 1.392.021 1.82.63.27.385.506.792.704 1.218.315.675.111 1.422-.364 1.891l-.814.806c-.049.048-.098.147-.088.294.016.257.016.515 0 .772-.01.147.038.246.088.294l.814.806c.475.469.679 1.216.364 1.891a7.977 7.977 0 0 1-.704 1.217c-.428.61-1.176.807-1.82.63l-1.102-.302c-.067-.019-.177-.011-.3.071a5.909 5.909 0 0 1-.668.386c-.133.066-.194.158-.211.224l-.29 1.106c-.168.646-.715 1.196-1.458 1.26a8.006 8.006 0 0 1-1.402 0c-.743-.064-1.289-.614-1.458-1.26l-.289-1.106c-.018-.066-.079-.158-.212-.224a5.738 5.738 0 0 1-.668-.386c-.123-.082-.233-.09-.299-.071l-1.103.303c-.644.176-1.392-.021-1.82-.63a8.12 8.12 0 0 1-.704-1.218c-.315-.675-.111-1.422.363-1.891l.815-.806c.05-.048.098-.147.088-.294a6.214 6.214 0 0 1 0-.772c.01-.147-.038-.246-.088-.294l-.815-.806C.635 6.045.431 5.298.746 4.623a7.92 7.92 0 0 1 .704-1.217c.428-.61 1.176-.807 1.82-.63l1.102.302c.067.019.177.011.3-.071.214-.143.437-.272.668-.386.133-.066.194-.158.211-.224l.29-1.106C6.009.645 6.556.095 7.299.03 7.53.01 7.764 0 8 0Zm-.571 1.525c-.036.003-.108.036-.137.146l-.289 1.105c-.147.561-.549.967-.998 1.189-.173.086-.34.183-.5.29-.417.278-.97.423-1.529.27l-1.103-.303c-.109-.03-.175.016-.195.045-.22.312-.412.644-.573.99-.014.031-.021.11.059.19l.815.806c.411.406.562.957.53 1.456a4.709 4.709 0 0 0 0 .582c.032.499-.119 1.05-.53 1.456l-.815.806c-.081.08-.073.159-.059.19.162.346.353.677.573.989.02.03.085.076.195.046l1.102-.303c.56-.153 1.113-.008 1.53.27.161.107.328.204.501.29.447.222.85.629.997 1.189l.289 1.105c.029.109.101.143.137.146a6.6 6.6 0 0 0 1.142 0c.036-.003.108-.036.137-.146l.289-1.105c.147-.561.549-.967.998-1.189.173-.086.34-.183.5-.29.417-.278.97-.423 1.529-.27l1.103.303c.109.029.175-.016.195-.045.22-.313.411-.644.573-.99.014-.031.021-.11-.059-.19l-.815-.806c-.411-.406-.562-.957-.53-1.456a4.709 4.709 0 0 0 0-.582c-.032-.499.119-1.05.53-1.456l.815-.806c.081-.08.073-.159.059-.19a6.464 6.464 0 0 0-.573-.989c-.02-.03-.085-.076-.195-.046l-1.102.303c-.56.153-1.113.008-1.53-.27a4.44 4.44 0 0 0-.501-.29c-.447-.222-.85-.629-.997-1.189l-.289-1.105c-.029-.11-.101-.143-.137-.146a6.6 6.6 0 0 0-1.142 0ZM11 8a3 3 0 1 1-6 0 3 3 0 0 1 6 0ZM9.5 8a1.5 1.5 0 1 0-3.001.001A1.5 1.5 0 0 0 9.5 8Z"></path></svg>“Settings”\*\*\*\*。 如果看不到“设置”选项卡，请选择“<svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-kebab-horizontal" aria-label="kebab horizontal icon" role="img"><path d="M8 9a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3ZM1.5 9a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3Zm13 0a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3Z"></path></svg>”下拉菜单，然后单击“设置”。

   ![存储库标头的屏幕截图，其中显示了选项卡。 “设置”选项卡以深橙色边框突出显示。](/assets/images/help/repository/repo-actions-settings.png)
3. 在边栏的“Security”部分中，单击“<svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-codescan" aria-label="codescan" role="img"><path d="M8.47 4.97a.75.75 0 0 0 0 1.06L9.94 7.5 8.47 8.97a.75.75 0 1 0 1.06 1.06l2-2a.75.75 0 0 0 0-1.06l-2-2a.75.75 0 0 0-1.06 0ZM6.53 6.03a.75.75 0 0 0-1.06-1.06l-2 2a.75.75 0 0 0 0 1.06l2 2a.75.75 0 1 0 1.06-1.06L5.06 7.5l1.47-1.47Z"></path><path d="M12.246 13.307a7.501 7.501 0 1 1 1.06-1.06l2.474 2.473a.749.749 0 0 1-.326 1.275.749.749 0 0 1-.734-.215ZM1.5 7.5a6.002 6.002 0 0 0 3.608 5.504 6.002 6.002 0 0 0 6.486-1.117.748.748 0 0 1 .292-.293A6 6 0 1 0 1.5 7.5Z"></path></svg> Advanced Security”\*\*\*\*。
4. 在Dependabot下，为\*\*\*\*、Dependabot alerts和Dependabot security updates单击“启用”。
5. 如果您单击**启用**，则可以编辑Dependabot version updates在您的存储库的`dependabot.yml`目录中为您创建的默认GitHub配置文件`/.github`。
   若要为存储库启用 Dependabot version updates ，通常通过编辑默认文件并提交更改来配置此文件以满足需求。 有关示例，可以参考 [配置 Dependabot 版本更新](/zh/enterprise-cloud@latest/code-security/how-tos/secure-your-supply-chain/secure-your-dependencies/configure-version-updates#example-dependabotyml-file) 中提供的代码片段。

> \[!NOTE]
> 如果尚未为存储库启用依赖关系图，当您启用GitHub时，Dependabot将自动启用它。

有关配置每个Dependabot功能的详细信息，请参阅 [AUTOTITLE、](/zh/enterprise-cloud@latest/code-security/how-tos/secure-your-supply-chain/secure-your-dependencies/configure-dependabot-alerts)[配置 Dependabot 安全更新](/zh/enterprise-cloud@latest/code-security/how-tos/secure-your-supply-chain/secure-your-dependencies/configure-security-updates) 和 [配置 Dependabot 版本更新](/zh/enterprise-cloud@latest/code-security/how-tos/secure-your-supply-chain/secure-your-dependencies/configure-version-updates)。

## 查看 Dependabot alerts 存储库

如果为存储库启用了Dependabot alerts，可以在该存储库的Dependabot alerts选项卡上查看<svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-shield" aria-label="shield" role="img"><path d="M7.467.133a1.748 1.748 0 0 1 1.066 0l5.25 1.68A1.75 1.75 0 0 1 15 3.48V7c0 1.566-.32 3.182-1.303 4.682-.983 1.498-2.585 2.813-5.032 3.855a1.697 1.697 0 0 1-1.33 0c-2.447-1.042-4.049-2.357-5.032-3.855C1.32 10.182 1 8.566 1 7V3.48a1.75 1.75 0 0 1 1.217-1.667Zm.61 1.429a.25.25 0 0 0-.153 0l-5.25 1.68a.25.25 0 0 0-.174.238V7c0 1.358.275 2.666 1.057 3.86.784 1.194 2.121 2.34 4.366 3.297a.196.196 0 0 0 .154 0c2.245-.956 3.582-2.104 4.366-3.298C13.225 9.666 13.5 8.36 13.5 7V3.48a.251.251 0 0 0-.174-.237l-5.25-1.68ZM8.75 4.75v3a.75.75 0 0 1-1.5 0v-3a.75.75 0 0 1 1.5 0ZM9 10.5a1 1 0 1 1-2 0 1 1 0 0 1 2 0Z"></path></svg> Security and quality。 你可以使用上一节中启用了 Dependabot alerts 的分支存储库。

1. 在 GitHub 上，导航到存储库的主页面。

2. 在存储库名称下，单击 **<svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-shield" aria-label="shield" role="img"><path d="M7.467.133a1.748 1.748 0 0 1 1.066 0l5.25 1.68A1.75 1.75 0 0 1 15 3.48V7c0 1.566-.32 3.182-1.303 4.682-.983 1.498-2.585 2.813-5.032 3.855a1.697 1.697 0 0 1-1.33 0c-2.447-1.042-4.049-2.357-5.032-3.855C1.32 10.182 1 8.566 1 7V3.48a1.75 1.75 0 0 1 1.217-1.667Zm.61 1.429a.25.25 0 0 0-.153 0l-5.25 1.68a.25.25 0 0 0-.174.238V7c0 1.358.275 2.666 1.057 3.86.784 1.194 2.121 2.34 4.366 3.297a.196.196 0 0 0 .154 0c2.245-.956 3.582-2.104 4.366-3.298C13.225 9.666 13.5 8.36 13.5 7V3.48a.251.251 0 0 0-.174-.237l-5.25-1.68ZM8.75 4.75v3a.75.75 0 0 1-1.5 0v-3a.75.75 0 0 1 1.5 0ZM9 10.5a1 1 0 1 1-2 0 1 1 0 0 1 2 0Z"></path></svg> Security and quality** 选项卡。如果看不到“<svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-shield" aria-label="shield" role="img"><path d="M7.467.133a1.748 1.748 0 0 1 1.066 0l5.25 1.68A1.75 1.75 0 0 1 15 3.48V7c0 1.566-.32 3.182-1.303 4.682-.983 1.498-2.585 2.813-5.032 3.855a1.697 1.697 0 0 1-1.33 0c-2.447-1.042-4.049-2.357-5.032-3.855C1.32 10.182 1 8.566 1 7V3.48a1.75 1.75 0 0 1 1.217-1.667Zm.61 1.429a.25.25 0 0 0-.153 0l-5.25 1.68a.25.25 0 0 0-.174.238V7c0 1.358.275 2.666 1.057 3.86.784 1.194 2.121 2.34 4.366 3.297a.196.196 0 0 0 .154 0c2.245-.956 3.582-2.104 4.366-3.298C13.225 9.666 13.5 8.36 13.5 7V3.48a.251.251 0 0 0-.174-.237l-5.25-1.68ZM8.75 4.75v3a.75.75 0 0 1-1.5 0v-3a.75.75 0 0 1 1.5 0ZM9 10.5a1 1 0 1 1-2 0 1 1 0 0 1 2 0Z"></path></svg> Security and quality”选项卡，请选择 **<svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-kebab-horizontal" aria-label="kebab-horizontal" role="img"><path d="M8 9a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3ZM1.5 9a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3Zm13 0a1.5 1.5 0 1 0 0-3 1.5 1.5 0 0 0 0 3Z"></path></svg>** 下拉菜单，然后单击 **<svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-shield" aria-label="shield" role="img"><path d="M7.467.133a1.748 1.748 0 0 1 1.066 0l5.25 1.68A1.75 1.75 0 0 1 15 3.48V7c0 1.566-.32 3.182-1.303 4.682-.983 1.498-2.585 2.813-5.032 3.855a1.697 1.697 0 0 1-1.33 0c-2.447-1.042-4.049-2.357-5.032-3.855C1.32 10.182 1 8.566 1 7V3.48a1.75 1.75 0 0 1 1.217-1.667Zm.61 1.429a.25.25 0 0 0-.153 0l-5.25 1.68a.25.25 0 0 0-.174.238V7c0 1.358.275 2.666 1.057 3.86.784 1.194 2.121 2.34 4.366 3.297a.196.196 0 0 0 .154 0c2.245-.956 3.582-2.104 4.366-3.298C13.225 9.666 13.5 8.36 13.5 7V3.48a.251.251 0 0 0-.174-.237l-5.25-1.68ZM8.75 4.75v3a.75.75 0 0 1-1.5 0v-3a.75.75 0 0 1 1.5 0ZM9 10.5a1 1 0 1 1-2 0 1 1 0 0 1 2 0Z"></path></svg> Security and quality**。

3. 在边栏的“查找”部分中，选择 <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-dependabot" aria-label="dependabot" role="img"><path d="M5.75 7.5a.75.75 0 0 1 .75.75v1.5a.75.75 0 0 1-1.5 0v-1.5a.75.75 0 0 1 .75-.75Zm5.25.75a.75.75 0 0 0-1.5 0v1.5a.75.75 0 0 0 1.5 0v-1.5Z"></path><path d="M6.25 0h2A.75.75 0 0 1 9 .75V3.5h3.25a2.25 2.25 0 0 1 2.25 2.25V8h.75a.75.75 0 0 1 0 1.5h-.75v2.75a2.25 2.25 0 0 1-2.25 2.25h-8.5a2.25 2.25 0 0 1-2.25-2.25V9.5H.75a.75.75 0 0 1 0-1.5h.75V5.75A2.25 2.25 0 0 1 3.75 3.5H7.5v-2H6.25a.75.75 0 0 1 0-1.5ZM3 5.75v6.5c0 .414.336.75.75.75h8.5a.75.75 0 0 0 .75-.75v-6.5a.75.75 0 0 0-.75-.75h-8.5a.75.75 0 0 0-.75.75Z"></path></svg>**Dependabot**<svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-chevron-down" aria-label="chevron-down" role="img"><path d="M12.78 5.22a.749.749 0 0 1 0 1.06l-4.25 4.25a.749.749 0 0 1-1.06 0L3.22 6.28a.749.749 0 1 1 1.06-1.06L8 8.939l3.72-3.719a.749.749 0 0 1 1.06 0Z"></path></svg> 下拉菜单，然后单击“ **漏洞**”。

4. 查看Dependabot alerts页面上的公开警报。 默认情况下，该页面显示“打开”选项卡，其中列出了打开的警报。 （可以通过单击“已关闭”来查看任何已关闭的警报。）

   ![显示演示存储库的 Dependabot 警报列表的屏幕截图。](/assets/images/help/repository/dependabot-alerts-list-demo-repo.png)

   可以使用各种筛选器或标签在列表中进行筛选 Dependabot alerts 。 有关详细信息，请参阅“[查看和更新 Dependabot 警报](/zh/enterprise-cloud@latest/code-security/how-tos/manage-security-alerts/manage-dependabot-alerts/view-dependabot-alerts#prioritizing-dependabot-alerts)”。 您还可以通过使用 Dependabot 自动分类规则 来筛选出误报或您不感兴趣的警报。 有关详细信息，请参阅“[Dependabot 自动分类规则](/zh/enterprise-cloud@latest/code-security/concepts/supply-chain-security/dependabot-auto-triage-rules)”。

5. 单击 `javascript/package-lock.json` 文件中的“lodash 中的命令注入”警报。 警报的详细信息页将显示以下信息（请注意，某些信息可能不适用于所有警报）：

   * Dependabot 是否创建了将修复漏洞的拉取请求。 可以通过单击“查看安全更新”来查看建议的安全更新。
   * 涉及的包
   * 受影响版本
   * 已修补版本
   * 漏洞的简要说明

   ![演示存储库中警报的详细页面的屏幕截图，其中显示了主要信息。](/assets/images/help/repository/alert-details-page-demo-repo.png)

6. （可选）还可以浏览页面右侧的信息。 屏幕截图中显示的某些信息可能不适用于每个警报。

   * Severity
   * CVSS 指标：我们使用 CVSS 级别来分配严重性级别。 有关详细信息，请参阅“[GitHub 通告数据库](/zh/enterprise-cloud@latest/code-security/concepts/vulnerability-reporting-and-management/github-advisory-database#about-cvss-levels)”。
   * 标记
   * 弱点：与漏洞相关的 CWE 列表（如果适用）
   * CVE ID：漏洞的唯一 CVE 标识符（如果适用）
   * GHSA ID：GitHub Advisory Database
     上相应公告的唯一标识符。 有关详细信息，请参阅“[GitHub 通告数据库](/zh/enterprise-cloud@latest/code-security/concepts/vulnerability-reporting-and-management/github-advisory-database#about-ghsa-ids)”。
   * 导航到 GitHub Advisory Database
     上公告的选项
   * 用于查看受此漏洞影响的所有存储库的选项
   * 在 GitHub Advisory Database
     上建议改进此公告的选项

   ![演示存储库中警报的详细页面的屏幕截图，其中显示了页面右侧显示的信息。](/assets/images/help/repository/more-alert-details-demo-repo.png)

有关查看、确定优先级和排序 Dependabot alerts的详细信息，请参阅 [查看和更新 Dependabot 警报](/zh/enterprise-cloud@latest/code-security/how-tos/manage-security-alerts/manage-dependabot-alerts/view-dependabot-alerts)。

## 修复或消除 Dependabot 警报

可以在Dependabot alerts上修复或忽略GitHub。 让我们继续以分支存储库为例，以及上一节中描述的“lodash 中的命令注入”警报。

1. 请导航到存储库的Dependabot选项卡。 有关详细信息，请参阅上面的[“查看Dependabot alerts存储库”](#viewing-dependabot-alerts-for-your-repository)部分。
2. 单击警报。
3. 单击 `javascript/package-lock.json` 文件中的“lodash 中的命令注入”警报。
4. 查看警报。 您可以：
   * 通过单击“查看安全更新”来查看建议的安全更新。 这将打开由 Dependabot 生成并包含安全修复的拉取请求。

     ![Dependabot 为修复所选警报突出显示的安全漏洞而生成的拉取请求的屏幕截图。](/assets/images/help/repository/dependabot-pull-request-demo-repo.png)

     * 在拉取请求说明中，你可以单击“提交”\*\*\*\* 以浏览拉取请求中包含的提交。
     * 还可以单击 **Dependabot 命令和选项** ，了解可用于与拉取请求交互的命令。
     * 当您准备好更新依赖项并解决漏洞时，合并拉取请求。
   * 如果你决定要忽略警报
     * 返回警报详细信息页。

     * 在右上角，按下“**关闭警报**”。

       ![警报详细信息页面的屏幕截图，其中“Dismiss Alert”按钮、下拉菜单选项和“Dismissal comment”框用橙色框出。](/assets/images/help/repository/dismiss-alert-demo-repo.png)

     * 选择忽略警报的原因。

     * （可选）添加消除注释。 消除操作注释将添加到警报时间线，可在审核和报告期间用作理由。

     * 单击“消除警报”。 警报将不再会在警报列表的“未解决”\*\*\*\* 选项卡中显示，但可以在“已解决”\*\*\*\* 选项卡中查看。

有关查看和更新 Dependabot alerts的详细信息，请参阅 [查看和更新 Dependabot 警报](/zh/enterprise-cloud@latest/code-security/how-tos/manage-security-alerts/manage-dependabot-alerts/view-dependabot-alerts#reviewing-and-fixing-alerts)。

## 故障排除

在以下情况下，可能需要执行一些故障排除：

* Dependabot 被阻止创建拉取请求以修复警报，或
* 所 Dependabot 报告的信息不是你所期望的信息。

有关详细信息，请分别参阅 [Dependabot 错误](/zh/enterprise-cloud@latest/code-security/reference/supply-chain-security/troubleshoot-dependabot/dependabot-errors) 和 [脆弱性依赖检测](/zh/enterprise-cloud@latest/code-security/reference/supply-chain-security/troubleshoot-dependabot/vulnerability-detection)。

## 后续步骤

有关配置 Dependabot 更新的详细信息，请参阅 [配置 Dependabot 安全更新](/zh/enterprise-cloud@latest/code-security/how-tos/secure-your-supply-chain/secure-your-dependencies/configure-security-updates) 和 [配置 Dependabot 版本更新](/zh/enterprise-cloud@latest/code-security/how-tos/secure-your-supply-chain/secure-your-dependencies/configure-version-updates)。

有关为组织配置 Dependabot 的详细信息，请参阅 [配置 Dependabot 警报](/zh/enterprise-cloud@latest/code-security/how-tos/secure-your-supply-chain/secure-your-dependencies/configure-dependabot-alerts#managing-dependabot-alerts-for-your-organization)。

有关查看 Dependabot 打开的拉取请求的详细信息，请参阅 [管理依赖项更新的所有拉取请求](/zh/enterprise-cloud@latest/code-security/how-tos/secure-your-supply-chain/manage-your-dependency-security/manage-dependabot-prs#viewing-dependabot-pull-requests)。

有关促成 Dependabot alerts 的安全公告的详细信息，请参阅 [在 GitHub Advisory Database 中浏览安全公告](/zh/enterprise-cloud@latest/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/browse-advisory-database)。

有关配置Dependabot alerts通知的详细信息，请参阅[为 Dependabot 警报配置通知](/zh/enterprise-cloud@latest/code-security/how-tos/secure-your-supply-chain/manage-your-dependency-security/configure-dependabot-notifications)。