Skip to content

ci(dependabot): require green checks before auto-merge - #104

Merged
barad1tos merged 1 commit into
mainfrom
ci/dependabot-auto-merge
Sep 28, 2026
Merged

barad1tos merged 1 commit into
mainfrom
ci/dependabot-auto-merge

Conversation

@barad1tos

@barad1tos barad1tos commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

── Summary ─────────────────────────────────

Merge every Dependabot pull request automatically once the required checks on main pass. The current PR workflows skip some file-only changes, which can leave required checks unreported and prevent a reliable green gate.

── Changes ─────────────────────────────────

  • CI: Add a workflow that calls gh pr merge --auto --merge only for pull requests authored by dependabot[bot] in this repository. It does not filter by dependency, ecosystem, or SemVer level.
  • CI: Run the existing CI and CodeQL workflows on every pull request to main so protected checks are reported even for documentation-only changes. Push filters remain as they were.

── Validation ──────────────────────────────

  • pre-commit run check-yaml --files .github/workflows/build.yml .github/workflows/codeql.yml .github/workflows/dependabot-automerge.yml — passed.
  • pre-commit run zizmor --files .github/workflows/build.yml .github/workflows/codeql.yml .github/workflows/dependabot-automerge.yml — passed.
  • Parsed the three workflows and asserted the PR triggers, bot-only condition, permissions, and merge command — passed.
  • git diff --check — passed.
  • Pre-commit hooks — passed.

── Notes ───────────────────────────────────

The main ruleset already requires the existing 11 CI and review checks from their specific GitHub Apps with an up-to-date branch. The repository's auto-merge option is still disabled and will be enabled after this workflow is merged and verified.

Summary by Sourcery

Enable reliable Dependabot auto-merging by requiring complete protected checks on every pull request to main.

New Features:

  • Add automatic merge enablement for Dependabot pull requests after required checks pass.

Bug Fixes:

  • Ensure CI and CodeQL checks are reported for all pull requests targeting main, including documentation-only changes.

CI:

  • Update pull-request workflow triggers so protected CI and CodeQL checks run consistently for pull requests to main.

Dependabot pull requests still require manual merges after passing CI, and path filters can leave protected checks absent on a pull request.

- Add a bot-only workflow that enables GitHub auto-merge for every Dependabot pull request.
- Run CI and CodeQL on every pull request to main so required checks are always reported.

Impact: Dependabot updates can merge automatically once the required checks pass.
@sourcery-ai

sourcery-ai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Reviewer's Guide

The PR adds a bot- and repository-scoped workflow that enables merge-commit auto-merge for Dependabot pull requests, while removing pull-request path filters from CI and CodeQL so protected checks are reported for all changes targeting main; push path exclusions remain unchanged.

Sequence diagram for Dependabot auto-merge after required checks

sequenceDiagram
    actor Dependabot
    participant GitHub as GitHub Pull Request
    participant AutoMerge as Dependabot auto-merge workflow
    participant Checks as CI and CodeQL
    participant Repository as Repository

    Dependabot->>GitHub: Open or update pull request to main
    GitHub->>AutoMerge: Trigger pull_request
    GitHub->>Checks: Run CI and CodeQL for every pull request
    AutoMerge->>AutoMerge: Check pull_request.user.login == dependabot[bot]
    AutoMerge->>Repository: gh pr merge --auto --merge PR_URL
    Repository-->>GitHub: Enable merge-commit auto-merge
    GitHub->>GitHub: Merge when required checks pass
Loading

File-Level Changes

Change Details Files
Ensure protected CI checks are emitted for every pull request targeting main, including file-only changes.
  • Keep push path exclusions for documentation and metadata-only changes.
  • Remove pull-request path exclusions from the CI and CodeQL workflows.
  • Preserve the existing main-branch pull request triggers and workflow behavior otherwise.
.github/workflows/build.yml
.github/workflows/codeql.yml
Enable repository-scoped Dependabot pull requests to enter GitHub auto-merge once required checks pass.
  • Trigger on Dependabot pull request lifecycle events targeting main.
  • Restrict execution to Dependabot-authored pull requests in barad1tos/noxctl.
  • Grant contents and pull-request write permissions and invoke gh pr merge --auto --merge.
  • Leave dependency type, ecosystem, and SemVer filtering unrestricted.
.github/workflows/dependabot-automerge.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T19:30:17.517989Z fa07f7a PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path=".github/workflows/dependabot-automerge.yml" line_range="3-4" />
<code_context>
+    if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository == 'barad1tos/noxctl'
+    runs-on: ubuntu-latest
+    steps:
+      - name: Enable auto-merge
+        run: gh pr merge --auto --merge "$PR_URL"
+        env:
</code_context>
<issue_to_address>
**issue (bug_risk):** The `gh pr merge --auto --merge` command receives the `GITHUB_TOKEN` from a `pull_request` workflow, but GitHub grants Dependabot-triggered pull-request workflows a read-only token regardless of the requested `contents: write` and `pull-requests: write` permissions. The command therefore fails with an authorization error and never enables auto-merge.

**Triggers:** When this workflow runs for a Dependabot pull request.

**Suggested fix:** Run the trusted merge operation from a `pull_request_target` workflow without checking out or executing pull-request code, or authenticate with a GitHub App/PAT that has the required merge permissions.

```suggestion
on:
  pull_request_target:
```
</issue_to_address>

Sourcery assessment

Needs a human reviewer. 1 finding to address first, and this grants a GitHub Actions workflow write access and enables Dependabot pull requests to merge automatically; if branch protection does not require the intended checks, an unsafe dependency change could be merged and remain after this workflow is reverted. Reverting stops future auto-merges, but already merged changes require separate remediation.

Blocking findings: .github/workflows/dependabot-automerge.yml:4


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Comment thread .github/workflows/dependabot-automerge.yml
@barad1tos
barad1tos merged commit 94b4640 into main Sep 28, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant