# PSA: Use Dependabot to update GitHub actions automatically

**URL:** <https://discourse.julialang.org/t/psa-use-dependabot-to-update-github-actions-automatically/96001>\
**Category:** Tooling\
**Tags:** announcement\
**Created:** [March 13, 2023, 12:59pm UTC](https://discourse.julialang.org/t/psa-use-dependabot-to-update-github-actions-automatically/96001 "2023-03-13T12:59:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ranocha](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ranocha/32/35588_2.png) [@ranocha](https://discourse.julialang.org/u/ranocha)\
**Post date:** [March 13, 2023, 12:59pm UTC](https://discourse.julialang.org/t/psa-use-dependabot-to-update-github-actions-automatically/96001/1 "2023-03-13T12:59:35Z")

</div>

GitHub offers [Dependabot](https://github.com/dependabot) to update GitHub actions automatically. I found this quite useful for my own packages. The [SciML organization](https://github.com/SciML) and the [Trixi.jl framework](https://github.com/trixi-framework) have already enabled it in many repositories, the remaining ones will be processed soon. You basically need to create a file `.github/dependabot.yml` with the following content:

```bash
# https://docs.github.com/github/administering-a-repository/configuration-options-for-dependency-updates
version: 2
updates:
  - package-ecosystem: "github-actions"
    directory: "/" # Location of package manifests
    schedule:
      interval: "weekly"

```

See [enable dependabot for GitHub actions by ranocha · Pull Request #37 · SciML/MuladdMacro.jl · GitHub](https://github.com/SciML/MuladdMacro.jl/pull/37) for an example.

Hope this is useful for some of you!

---

<div class="post-metadata">

**Author:** ![ranocha](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ranocha/32/35588_2.png) [@ranocha](https://discourse.julialang.org/u/ranocha)\
**Post date:** [March 14, 2023, 1:17pm UTC](https://discourse.julialang.org/t/psa-use-dependabot-to-update-github-actions-automatically/96001/2 "2023-03-14T13:17:42Z")

</div>

To be more specific, you can see Dependabot as an anlog of CompatHelper for GitHub actions dependencies such as `actions/checkout@v2`. Based on semver, you will not use `actions/checkout@v2` with this setup. Dependabot will create a PR updating such a line to `actions/checkout@v3`. This will fix deprecation warnings such as

```julia
Node.js 12 actions are deprecated. Please update the following actions to use Node.js 16:
actions/checkout@v2, actions/cache@v2, codecov/codecov-action@v2. 
For more information see: https://github.blog/changelog/2022-09-22-github-actions-all-actions-will-begin-running-on-node16-instead-of-node12/.

```

That’s handled by updating the GitHub actions mentioned there to there new major version - which dependabot will do for you by submitting PRs. See also [enable dependabot for GitHub actions by ranocha · Pull Request #42 · JuliaArrays/TiledIteration.jl · GitHub](https://github.com/JuliaArrays/TiledIteration.jl/pull/42)

---

<div class="post-metadata">

**Author:** ![Elrod](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/elrod/32/22461_2.png) [@Elrod](https://discourse.julialang.org/u/Elrod)\
**Post date:** [March 15, 2023, 6:21pm UTC](https://discourse.julialang.org/t/psa-use-dependabot-to-update-github-actions-automatically/96001/3 "2023-03-15T18:21:19Z")

</div>

Unfortunately, we can’t currently depend on Dependabot to upgrade workflows like CompatHelper. I realized I need to go back to some repos and manually update it.

---

<div class="post-metadata">

**Author:** ![nsajko](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/nsajko/32/221187_2.png) [@nsajko](https://discourse.julialang.org/u/nsajko)\
**Post date:** [November 20, 2025, 8:18am UTC](https://discourse.julialang.org/t/psa-use-dependabot-to-update-github-actions-automatically/96001/4 "2025-11-20T08:18:24Z")

</div>

Dependabot now has support for Julia packages, too, allowing it to replace CompatHelper, the Julia-specific alternative:

- [This month in Julia world - 2025-10](https://discourse.julialang.org/t/this-month-in-julia-world-2025-10/133753)
