chore(deps-dev): bump time-machine from 3.5.0 to 3.5.1 #461
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Dependabot auto-merge (v0.10.6 plan 136 Change A2) | |
| # | |
| # Auto-merges dependabot PRs EXCEPT those that touch `.github/**` | |
| # (`paths-ignore`). When the diff does touch `.github/**`, this | |
| # workflow does not fire at all, leaving the PR for human review — | |
| # the only reliable way to prevent dependabot from auto-merging an | |
| # invalid major tag on a GitHub Action (see plans/136). | |
| # | |
| # Combined with the `ignore:` block on the `github-actions` ecosystem | |
| # in .github/dependabot.yml (cap majors for stale actions), this | |
| # guarantees: | |
| # - Minor + patch bumps to .github/workflows/** land automatically. | |
| # - Major bumps to any GHA action are filtered by `ignore:` | |
| # (dependabot doesn't even open those PRs). | |
| # - Anything else that touches .github/** (catches the case where | |
| # a minor/patch bump is still incorrect) requires a human. | |
| # | |
| # ENTERPRISE ORG WARNING (v0.10.6 plan 136 round-3 code-review fix): | |
| # On repos hosted in organizations where the default `GITHUB_TOKEN` | |
| # is restricted to read-only at the org level, the `gh pr merge --auto` | |
| # call below will fail with `403 Resource not accessible by integration`. | |
| # Before relying on this workflow, the org admin MUST either: | |
| # (a) allow-list this workflow's permissions in the org's | |
| # "GitHub Actions" page (`GITHUB_TOKEN` -> choose this workflow | |
| # -> set permissions to write on contents + pull-requests), or | |
| # (b) enable the repo's "Allow GitHub Actions to create and approve | |
| # pull requests" setting in repo Settings -> Actions -> General. | |
| # Without either (a) or (b), auto-merge silently fails on every PR and | |
| # this workflow becomes a no-op. Defense-in-depth: combine with the | |
| # branch-protection rule in plans/137 so even if auto-merge fails, | |
| # the workflow still cannot land an invalid tag on `main`. | |
| name: Dependabot auto-merge | |
| on: | |
| pull_request: | |
| types: [opened, synchronize, reopened] | |
| paths-ignore: | |
| - '.github/**' | |
| # v0.10.6 plan 136 (code-review fix): prevent rapid | |
| # `opened` -> `synchronize` re-runs from racing on the same PR. | |
| # Without this, two `gh pr merge --auto --squash` invocations | |
| # can conflict on the GitHub merge queue. | |
| concurrency: | |
| group: ${{ github.event.pull_request.number }} | |
| cancel-in-progress: false | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| jobs: | |
| dependabot-auto-merge: | |
| # Only auto-merge when dependabot opened the PR. Non-dependabot | |
| # PRs always require human review regardless of path. | |
| if: github.actor == 'dependabot[bot]' | |
| runs-on: ubuntu-latest | |
| steps: | |
| # v0.10.6 plan 137 (round-4 code-review fix): surface the | |
| # ENTERPRISE ORG WARNING in the Actions UI itself, not just | |
| # buried in the YAML comment. A misconfigured org admin | |
| # sees this annotation in the run summary immediately. | |
| - name: Enterprise org GITHUB_TOKEN check | |
| if: github.actor == 'dependabot[bot]' | |
| run: | | |
| echo "::warning::If this auto-merge fails with '403 Resource not accessible by integration', your org's default GITHUB_TOKEN is restricted to read-only. See the workflow header comment for remediation (token allow-list OR 'Allow GitHub Actions to create and approve pull requests')." | |
| - name: Dependabot metadata | |
| id: metadata | |
| uses: dependabot/fetch-metadata@v2 | |
| with: | |
| github-token: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Auto-merge patch + minor for non-workflow ecosystems | |
| if: | | |
| steps.metadata.outputs.update-type == 'version-update:semver-patch' || | |
| steps.metadata.outputs.update-type == 'version-update:semver-minor' | |
| # v0.10.6 plan 136 (code-review fix): append the update-type to | |
| # the GitHub step summary so a future post-mortem can audit | |
| # exactly which ecosystem + bump type landed. Helps isolate | |
| # the next dependabot-metadata regression. | |
| run: | | |
| echo "dependabot-auto-merge :: ecosystem=${{ steps.metadata.outputs.package-ecosystem }} update-type=${{ steps.metadata.outputs.update-type }} dependency=${{ steps.metadata.outputs.dependency-name }}" | |
| gh pr merge --auto --squash "$PR_URL" | |
| env: | |
| PR_URL: ${{ github.event.pull_request.html_url }} | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} |