From 6cd0609d8c343003f9cd7deec04c54cf9f7e3547 Mon Sep 17 00:00:00 2001 From: CMaintz Date: Sun, 27 Sep 2026 20:17:00 +0200 Subject: [PATCH] feat(bootstrap): auto-merge prune baseline PRs MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit A prune only ever SHRINKS the snooze baseline (ruleset-guard verifies), so arm 'gh pr merge --auto' on it — it lands once required checks pass, no rubber-stamp. A first-time snooze SEEDS the baseline (regen step now emits pruned=true/false), so that stays human-reviewed. Consumers need repo 'Allow auto-merge' on. Backports jobbuddy#153. --- .github/workflows/bootstrap.yml | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/.github/workflows/bootstrap.yml b/.github/workflows/bootstrap.yml index 6c6fa8f..a8bd7b7 100644 --- a/.github/workflows/bootstrap.yml +++ b/.github/workflows/bootstrap.yml @@ -74,14 +74,17 @@ jobs: PLUGIN: ${{ inputs.habit_hooks_plugin }} run: pip install --disable-pip-version-check habit-hooks "$PLUGIN" - name: Regenerate (prune to shrink; snooze only to create) + id: regen run: | export PATH="$PWD/node_modules/.bin:$PATH" # --no-snooze feeds RAW findings: prune needs them to see which baselined # files are now clean; snooze needs them to baseline all current smells. if [ -f .habit-hooks/snooze.json ]; then habit-sensors --all --no-snooze | habit-snooze --prune + echo "pruned=true" >> "$GITHUB_OUTPUT" # shrink-only → safe to auto-merge else habit-sensors --all --no-snooze | habit-snooze --snooze + echo "pruned=false" >> "$GITHUB_OUTPUT" # first-time seed → human-reviewed fi - name: Open a PR with the refreshed baseline working-directory: . @@ -109,3 +112,10 @@ jobs: --title "chore: refresh habit-hooks snooze baseline" \ --body "Regenerated by the bootstrap workflow (\`--prune\` where a baseline existed, so it can only **shrink** — a new entry would mean a smell slipped past the gate). Touches only snooze.json, no source, so ruleset-guard passes with the label." \ --label ruleset-change + # A prune only ever SHRINKS the baseline (ruleset-guard verifies), so arm + # auto-merge — it lands once the required checks pass, no rubber-stamp needed. + # A first-time snooze SEEDS the baseline; leave that for human review. Requires + # the consumer repo to have "Allow auto-merge" on + branch-protection checks. + if [ "${{ steps.regen.outputs.pruned }}" = "true" ]; then + gh pr merge "$branch" --auto --merge && echo "auto-merge armed for $branch" + fi