Repository navigation
ci(dependabot): require green checks before auto-merge - #104
Conversation
Dependabot pull requests still require manual merges after passing CI, and path filters can leave protected checks absent on a pull request. - Add a bot-only workflow that enables GitHub auto-merge for every Dependabot pull request. - Run CI and CodeQL on every pull request to main so required checks are always reported. Impact: Dependabot updates can merge automatically once the required checks pass.
Reviewer's GuideThe PR adds a bot- and repository-scoped workflow that enables merge-commit auto-merge for Dependabot pull requests, while removing pull-request path filters from CI and CodeQL so protected checks are reported for all changes targeting main; push path exclusions remain unchanged. Sequence diagram for Dependabot auto-merge after required checkssequenceDiagram
actor Dependabot
participant GitHub as GitHub Pull Request
participant AutoMerge as Dependabot auto-merge workflow
participant Checks as CI and CodeQL
participant Repository as Repository
Dependabot->>GitHub: Open or update pull request to main
GitHub->>AutoMerge: Trigger pull_request
GitHub->>Checks: Run CI and CodeQL for every pull request
AutoMerge->>AutoMerge: Check pull_request.user.login == dependabot[bot]
AutoMerge->>Repository: gh pr merge --auto --merge PR_URL
Repository-->>GitHub: Enable merge-commit auto-merge
GitHub->>GitHub: Merge when required checks pass
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Hey - I've found 1 issue
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path=".github/workflows/dependabot-automerge.yml" line_range="3-4" />
<code_context>
+ if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository == 'barad1tos/noxctl'
+ runs-on: ubuntu-latest
+ steps:
+ - name: Enable auto-merge
+ run: gh pr merge --auto --merge "$PR_URL"
+ env:
</code_context>
<issue_to_address>
**issue (bug_risk):** The `gh pr merge --auto --merge` command receives the `GITHUB_TOKEN` from a `pull_request` workflow, but GitHub grants Dependabot-triggered pull-request workflows a read-only token regardless of the requested `contents: write` and `pull-requests: write` permissions. The command therefore fails with an authorization error and never enables auto-merge.
**Triggers:** When this workflow runs for a Dependabot pull request.
**Suggested fix:** Run the trusted merge operation from a `pull_request_target` workflow without checking out or executing pull-request code, or authenticate with a GitHub App/PAT that has the required merge permissions.
```suggestion
on:
pull_request_target:
```
</issue_to_address>Sourcery assessment
Needs a human reviewer. 1 finding to address first, and this grants a GitHub Actions workflow write access and enables Dependabot pull requests to merge automatically; if branch protection does not require the intended checks, an unsafe dependency change could be merged and remain after this workflow is reverted. Reverting stops future auto-merges, but already merged changes require separate remediation.
Blocking findings: .github/workflows/dependabot-automerge.yml:4
── Summary ─────────────────────────────────
Merge every Dependabot pull request automatically once the required checks on main pass. The current PR workflows skip some file-only changes, which can leave required checks unreported and prevent a reliable green gate.
── Changes ─────────────────────────────────
gh pr merge --auto --mergeonly for pull requests authored bydependabot[bot]in this repository. It does not filter by dependency, ecosystem, or SemVer level.── Validation ──────────────────────────────
pre-commit run check-yaml --files .github/workflows/build.yml .github/workflows/codeql.yml .github/workflows/dependabot-automerge.yml— passed.pre-commit run zizmor --files .github/workflows/build.yml .github/workflows/codeql.yml .github/workflows/dependabot-automerge.yml— passed.git diff --check— passed.── Notes ───────────────────────────────────
The main ruleset already requires the existing 11 CI and review checks from their specific GitHub Apps with an up-to-date branch. The repository's auto-merge option is still disabled and will be enabled after this workflow is merged and verified.
Summary by Sourcery
Enable reliable Dependabot auto-merging by requiring complete protected checks on every pull request to main.
New Features:
Bug Fixes:
CI: