Skip to content

tools: skip dependency update if PR has non-bot commits - #66503

Open
marco-ippolito wants to merge 1 commit into
nodejs:mainfrom
marco-ippolito:tools-skip-update-on-human-commits
Open

marco-ippolito wants to merge 1 commit into
nodejs:mainfrom
marco-ippolito:tools-skip-update-on-human-commits

Conversation

@marco-ippolito

@marco-ippolito marco-ippolito commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

When a new version of a dependency comes out, it runs create pull request on the existing actions/tools-update-<id> branch. That force-pushes the branch and throws away any commits a collaborator pushed to fix the update, as happened in #66397 and #66146.

This adds a first step that checks the open PR for that branch. If any commit isn't authored by github-bot@iojs.org, the rest of the job is skipped for that dependency and a notice links to the PR. If there's no open PR, or it only has bot commits, the update runs as before.

When the tools-deps-update workflow finds a new version of a
dependency, peter-evans/create-pull-request force-pushes the
Action's branch, discarding any commits a collaborator pushed to
the existing PR to fix the update.

Before running the updater, check whether the open PR for the
Action's branch contains commits not authored by the bot, and if so
skip the update for that dependency instead of overwriting them.

Signed-off-by: Marco Ippolito <marcoippolito54@gmail.com>
Assisted-by: claude:opus-5.5
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/actions
  • @nodejs/security-wg

@nodejs-github-bot nodejs-github-bot added the meta Issues and PRs related to the general management of the project. label Oct 4, 2026
# Updating the Action's PR force-pushes its branch, so skip the update
# if someone pushed their own commits to it to avoid discarding them.
env:
GH_TOKEN: ${{ secrets.GH_USER_TOKEN }}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You'd need to add pull-requests permission

Suggested change
GH_TOKEN: ${{ secrets.GH_USER_TOKEN }}
GH_TOKEN: ${{ github.token }}

Comment on lines +337 to +342
echo "update=false" >> "$GITHUB_OUTPUT"
else
echo "update=true" >> "$GITHUB_OUTPUT"
fi
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
if: steps.check-pr.outputs.update == 'true'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
echo "update=false" >> "$GITHUB_OUTPUT"
else
echo "update=true" >> "$GITHUB_OUTPUT"
fi
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
if: steps.check-pr.outputs.update == 'true'
echo "hasNonBotCommits=true" >> "$GITHUB_OUTPUT"
fi
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
if: steps.check-pr.outputs.hasNonBotCommits != 'true'

- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Check for non-bot commits on the existing pull request
id: check-pr
if: github.event_name == 'schedule' || inputs.id == 'all' || inputs.id == matrix.id

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IMO it would make sense to only run that check on schedule, if someone ran a manual update, they likely meant to override the existing PR

Suggested change
if: github.event_name == 'schedule' || inputs.id == 'all' || inputs.id == matrix.id
# When 'inputs.id == matrix.id', non-bot commits are being overwritten
if: github.event_name == 'schedule' || inputs.id == 'all'

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

meta Issues and PRs related to the general management of the project.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants