Skip to content

ci: テスト成功後にDependabotのtagpr更新を自動マージ - #24

Merged
kazeburo merged 2 commits into
mainfrom
codex/auto-merge-tagpr
Oct 8, 2026
Merged

kazeburo merged 2 commits into
mainfrom
codex/auto-merge-tagpr

Conversation

@kazeburo

@kazeburo kazeburo commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

User description

変更内容

Dependabot による Songmu/tagpr のみの更新を、最新コミットのテスト成功後に自動マージします。既存の dependencies グループの PR でも実際の変更が tagpr の参照更新だけなら対象になります。今後の更新は専用グループに分離します。

  • test / Tests / CI の完了を起点に、PR の作成者・対象ブランチ・最新 SHA・差分・最新のテスト実行を確認します。
  • 読み取りには GITHUB_TOKEN、マージには現在のリポジトリに限定した既存 GitHub App のトークンを使用し、マージ後の push で既存の tagpr も起動させます。
  • PR のコードや成果物を実行せず、マージ API に検証済み SHA を指定します。
  • 共通ワークフローを既存の36リポジトリ向けファイル同期に追加します。github-common 自身にも適用します。

導入条件

対象リポジトリで既存 App と Actions Secrets CLIENT_ID / APP_PRIVATE_KEY を利用可能にしてください。App の Contents / Pull requests の読み書き権限を使用し、Actions の権限追加は不要です。既存のブランチ保護や ruleset の bypass 対象には追加しません。

この PR のマージと通常の tagpr リリース後、各リポジトリに作られる同期 PR をマージすると有効になります。既にテスト完了済みの Dependabot PR は導入後にテストを再実行してください。別の必須チェックが遅れて完了する場合もテストの再実行が必要です。

検証

  • node --test tests/*.test.cjs: 24ケース成功
  • YAML の構文確認、git diff --check: 成功
  • テスト失敗・古い成功結果・追加コミット・他依存更新の混在・人による PR・fork・draft を除外することを検証
  • 実際の GitHub App によるマージと後続 tagpr の起動は未検証

PR Type

Enhancement, Tests, Documentation


Description

  • Auto-merge verified Dependabot Songmu/tagpr reference updates.

  • Separate tagpr updates into a Dependabot group.

  • Sync the workflow across target repositories.

  • Test rejection of unsafe or stale updates.


Diagram Walkthrough

flowchart LR
  tests["Successful test workflow"] --> verify["Verify PR, SHA, and tagpr-only diff"]
  verify --> token["Create repository-scoped App token"]
  token --> merge["Merge verified SHA"]
Loading

File Walkthrough

Relevant files
Configuration changes
3 files
dependabot-for-sync.yml
Separate synced `tagpr` updates from other dependencies   
+5/-0     
dependabot.yml
Group local `tagpr` updates separately from dependencies 
+5/-0     
files-sync-config.yaml
Include auto-merge workflow in repository file synchronization
+1/-0     
Enhancement
1 files
dependabot-auto-merge.yml
Verify tested tagpr-only changes before App-backed merge 
+134/-0 
Tests
2 files
test.yml
Run auto-merge policy tests on pushes and PRs                       
+15/-0   
dependabot-auto-merge.test.cjs
Test merge eligibility and rejection of unsafe changes     
+79/-0   
Documentation
1 files
README.md
Document auto-merge safeguards, rollout, and required credentials
+46/-0   

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

PR Reviewer Guide 🔍

(Review updated until commit 5dbda49)

Here are some key observations to aid the review process:

⏱️ Estimated effort to review: 3 🔵🔵🔵⚪⚪
🧪 PR contains tests
🔒 No security concerns identified
⚡ Recommended focus areas for review

Failed tests ignored

The latest-run lookup filters by the triggering event. In a repository that runs this test workflow on both push and pull_request, a successful push run can therefore trigger a merge even if a newer PR run failed, unless branch protection independently blocks it.

// Reject a superseded success or a pending/failed rerun for this exact head.
const runs = await github.paginate(github.rest.actions.listWorkflowRuns, {
  owner, repo, workflow_id: run.workflow_id, head_sha: pr.head.sha,
  branch: pr.head.ref, event: run.event, per_page: 100,
});
const latest = runs.sort((a, b) => b.id - a.id)[0];
if (!latest || latest.id !== run.id || latest.status !== 'completed' ||
    latest.conclusion !== 'success' || latest.run_attempt !== run.run_attempt) continue;
PR tests skipped

For pull_request runs, the workflow run's head_sha can be the synthetic merge commit rather than the PR branch's head commit. Comparing it directly with pr.head.sha then skips an otherwise eligible PR, so repositories with only PR-triggered tests may never auto-merge.

if (pr.user.login !== 'dependabot[bot]' || pr.draft ||
    pr.head.repo?.full_name !== fullName || pr.head.sha !== run.head_sha ||
    pr.base.ref !== context.payload.repository.default_branch) continue;
✅ Resolved findings

.github/workflows/dependabot-auto-merge.yml:49-51

PR Tests Skipped

For pull_request workflows, GitHub reports the test run's head SHA as the synthetic merge commit, not the PR head SHA. The equality check therefore skips valid Dependabot PRs in repositories that run tests only on pull_request.

.github/workflows/dependabot-auto-merge.yml:94-97

Merge Rejected

If a branch requires linear history while the repository also allows merge commits, this always selects merge. GitHub rejects that method for the protected branch, even when squash or rebase merging is available.

Comment thread .github/workflows/dependabot-auto-merge.yml Outdated
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Persistent review updated to latest commit 5dbda49

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

PR Code Suggestions ✨

No code suggestions found for the PR.

@kazeburo
kazeburo merged commit c0c0460 into main Oct 8, 2026
3 checks passed
@kazeburo
kazeburo deleted the codex/auto-merge-tagpr branch October 8, 2026 14:12
@github-actions github-actions Bot mentioned this pull request Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant