Skip to content

chore(deps-dev): bump time-machine from 3.5.0 to 3.5.1 #461

chore(deps-dev): bump time-machine from 3.5.0 to 3.5.1

chore(deps-dev): bump time-machine from 3.5.0 to 3.5.1 #461

# Dependabot auto-merge (v0.10.6 plan 136 Change A2)
#
# Auto-merges dependabot PRs EXCEPT those that touch `.github/**`
# (`paths-ignore`). When the diff does touch `.github/**`, this
# workflow does not fire at all, leaving the PR for human review —
# the only reliable way to prevent dependabot from auto-merging an
# invalid major tag on a GitHub Action (see plans/136).
#
# Combined with the `ignore:` block on the `github-actions` ecosystem
# in .github/dependabot.yml (cap majors for stale actions), this
# guarantees:
# - Minor + patch bumps to .github/workflows/** land automatically.
# - Major bumps to any GHA action are filtered by `ignore:`
# (dependabot doesn't even open those PRs).
# - Anything else that touches .github/** (catches the case where
# a minor/patch bump is still incorrect) requires a human.
#
# ENTERPRISE ORG WARNING (v0.10.6 plan 136 round-3 code-review fix):
# On repos hosted in organizations where the default `GITHUB_TOKEN`
# is restricted to read-only at the org level, the `gh pr merge --auto`
# call below will fail with `403 Resource not accessible by integration`.
# Before relying on this workflow, the org admin MUST either:
# (a) allow-list this workflow's permissions in the org's
# "GitHub Actions" page (`GITHUB_TOKEN` -> choose this workflow
# -> set permissions to write on contents + pull-requests), or
# (b) enable the repo's "Allow GitHub Actions to create and approve
# pull requests" setting in repo Settings -> Actions -> General.
# Without either (a) or (b), auto-merge silently fails on every PR and
# this workflow becomes a no-op. Defense-in-depth: combine with the
# branch-protection rule in plans/137 so even if auto-merge fails,
# the workflow still cannot land an invalid tag on `main`.
name: Dependabot auto-merge
on:
pull_request:
types: [opened, synchronize, reopened]
paths-ignore:
- '.github/**'
# v0.10.6 plan 136 (code-review fix): prevent rapid
# `opened` -> `synchronize` re-runs from racing on the same PR.
# Without this, two `gh pr merge --auto --squash` invocations
# can conflict on the GitHub merge queue.
concurrency:
group: ${{ github.event.pull_request.number }}
cancel-in-progress: false
permissions:
contents: write
pull-requests: write
jobs:
dependabot-auto-merge:
# Only auto-merge when dependabot opened the PR. Non-dependabot
# PRs always require human review regardless of path.
if: github.actor == 'dependabot[bot]'
runs-on: ubuntu-latest
steps:
# v0.10.6 plan 137 (round-4 code-review fix): surface the
# ENTERPRISE ORG WARNING in the Actions UI itself, not just
# buried in the YAML comment. A misconfigured org admin
# sees this annotation in the run summary immediately.
- name: Enterprise org GITHUB_TOKEN check
if: github.actor == 'dependabot[bot]'
run: |
echo "::warning::If this auto-merge fails with '403 Resource not accessible by integration', your org's default GITHUB_TOKEN is restricted to read-only. See the workflow header comment for remediation (token allow-list OR 'Allow GitHub Actions to create and approve pull requests')."
- name: Dependabot metadata
id: metadata
uses: dependabot/fetch-metadata@v2
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
- name: Auto-merge patch + minor for non-workflow ecosystems
if: |
steps.metadata.outputs.update-type == 'version-update:semver-patch' ||
steps.metadata.outputs.update-type == 'version-update:semver-minor'
# v0.10.6 plan 136 (code-review fix): append the update-type to
# the GitHub step summary so a future post-mortem can audit
# exactly which ecosystem + bump type landed. Helps isolate
# the next dependabot-metadata regression.
run: |
echo "dependabot-auto-merge :: ecosystem=${{ steps.metadata.outputs.package-ecosystem }} update-type=${{ steps.metadata.outputs.update-type }} dependency=${{ steps.metadata.outputs.dependency-name }}"
gh pr merge --auto --squash "$PR_URL"
env:
PR_URL: ${{ github.event.pull_request.html_url }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}