Skip to content

chore(ci): auto-merge Dependabot patch/minor PRs#1188

Merged
bagelbits merged 1 commit into
mainfrom
chore/dependabot-auto-merge
Jul 20, 2026
Merged

chore(ci): auto-merge Dependabot patch/minor PRs#1188
bagelbits merged 1 commit into
mainfrom
chore/dependabot-auto-merge

Conversation

@bagelbits

Copy link
Copy Markdown
Collaborator

What

Adds .github/workflows/dependabot-auto-merge.yml: approves and enables auto-merge on Dependabot patch/minor PRs.

How it works

  • Triggers on pull_request_target, gated to github.actor == 'dependabot[bot]'.
  • dependabot/fetch-metadata classifies the update; major bumps are skipped (still need manual review).
  • Approves + gh pr merge --auto --squash. Auto-merge waits for required checks (Lint Code, Run tests, Validate PR title) before merging; delete_branch_on_merge cleans up.

Why a PAT instead of the deploy App

The main ruleset requires a code-owner review (CODEOWNERS = @bagelbits). A bot/App can't be a code owner, so an App approval wouldn't satisfy the gate — using it would force dropping require_code_owner_review, widening merge authority to all push collaborators. A code-owner PAT approves as the owner, so the ruleset stays untouched and human PRs are unaffected.

Setup required before this works

  • Repo secret DEPENDABOT_AUTOMERGE_TOKEN: fine-grained PAT owned by @bagelbits, scoped to this repo, Pull requests + Contents read/write.

Not included

  • Major-version auto-merge (intentional).
  • Dependabot PR grouping.

🤖 Generated with Claude Code

Add a workflow that approves and enables auto-merge on Dependabot
patch/minor PRs. Approval uses a code-owner PAT so the existing
code-owner review gate stays intact; major bumps still require manual
review, and all merges wait on required CI checks.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@bagelbits
bagelbits merged commit cafd071 into main Jul 20, 2026
5 checks passed
@bagelbits
bagelbits deleted the chore/dependabot-auto-merge branch July 20, 2026 22:57
bagelbits added a commit that referenced this pull request Jul 20, 2026
Follow-up hardening for the auto-merge workflow added in #1188, from a
security review.

## Changes

- **Gate on PR author, not triggerer.** `github.actor` reflects whoever
triggered the latest event (e.g. a re-run), not the PR author. Switch to
`github.event.pull_request.user.login == 'dependabot[bot]'` so the job
only runs for PRs actually opened by Dependabot.
- **Pin `dependabot/fetch-metadata` to a commit SHA** (`25dd0e3` #
v3.1.0) instead of the mutable `@v3` tag, closing the supply-chain
window on that step.

## Not changed (by design)

- Auto-approve/merge itself: intended feature. Code-owner review gate
stays enforced (PAT approves as the owner), CI checks still required,
major bumps still excluded.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant