Repository navigation
Auto-merge green Dependabot updates and group the pm toolchain into one daily PR - #143
Conversation
…ne daily PR Version bumps of @unbrained/pm-cli, pm-ops and pm-changelog are mechanical. Dependabot now checks npm daily and groups the pm toolchain (and other minor/patch updates) into single pull requests; a least-privilege workflow enables squash auto-merge for every non-major Dependabot PR, so it lands as soon as the required checks pass and a failing bump stays open as a defect. pm item: ops-k1lf
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 40 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (6)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Summary by CodeRabbit
WalkthroughDependabot npm checks now run daily and group toolchain updates separately from minor and patch dependency updates. A new pull-request workflow enables squash auto-merge for toolchain or non-major updates. Task records and the changelog document the automation and rollout. ChangesDependabot automation
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant Dependabot
participant GitHubActions
participant DependabotPR
participant GHCli
Dependabot->>DependabotPR: Create grouped update pull request
DependabotPR->>GitHubActions: Trigger pull-request workflow
GitHubActions->>DependabotPR: Fetch dependency metadata
GitHubActions->>GHCli: Run auto-merge for pm-toolchain or non-major update
GHCli->>DependabotPR: Enable squash auto-merge
Merge Risk: ⚪ Minimal · up to No concrete merge-blocking defect is established. Confirm that repository settings require both test checks before relying on green-only auto-merge. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The automation is narrowly restricted and does not execute pull-request code with its write token. However, faster unattended dependency adoption increases supply-chain exposure, and the required-check settings could not be verified. The review does not establish that failing updates can merge. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideThis PR changes npm Dependabot checks to daily grouped updates and adds a narrowly scoped workflow that enables squash auto-merge for green Dependabot PRs. The pm-toolchain group is treated as an exception to the normal semver-major hold because calendar-versioned year rollovers must propagate automatically, while repository settings permit auto-merge and delete merged branches. Sequence diagram for Dependabot auto-merge workflowsequenceDiagram
participant Dependabot
participant GitHubActions
participant Metadata
participant GitHub
participant BranchProtection
Dependabot->>GitHub: Open or update pull request
GitHub->>GitHubActions: pull_request event
GitHubActions->>Metadata: dependabot/fetch-metadata
Metadata-->>GitHubActions: dependency-group and update-type
alt pm-toolchain group
GitHubActions->>GitHub: gh pr merge --auto --squash
else non-major update
GitHubActions->>GitHub: gh pr merge --auto --squash
else other major update
GitHubActions-->>GitHub: No auto-merge
end
GitHub->>BranchProtection: Check test (22) and test (26)
BranchProtection-->>GitHub: Allow merge when checks pass
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
pm item: ops-k1lf
|
@coderabbitai full review |
✅ Action performedFull review finished. |
…sions Review feedback: an update that fetch-metadata cannot classify must not auto-merge, so the condition now requires semver-minor or semver-patch outside the calendar-versioned pm-toolchain group. The job's write scopes are documented, the dependencies group selects every package explicitly, and the item's acceptance criteria name the pm-toolchain exception. pm item: ops-k1lf
|
@coderabbitai full review |
|
Rate Limit Exceeded
|
What
.github/dependabot.yml: npm is checked daily;@unbrained/pm-cliandpm-*packages arrive as onepm-toolchainPR, other minor/patch updates as onedependenciesPR. Other ecosystems are unchanged..github/workflows/dependabot-auto-merge.yml: for Dependabot PRs only (and only inunbraind),dependabot/fetch-metadata(SHA-pinned v3.1.0) classifies the update; thepm-toolchaingroup (calendar-versioned, so a year rollover reads as semver-major) and every other non-major update getgh pr merge --auto --squash. Workflow default permissions are{}; the job alone getscontents: write+pull-requests: write.Why
Fleet rule ([companion pm-cli-website-6d05]): a pm CLI release must reach every package without a hand-written certification PR. Branch protection still requires
test (22),test (26), so nothing merges red; a bump that fails CI stays open as a real defect. Major updates still need a person. Same change as the reviewed pilot unbraind/pm-presets#118.pm item
Summary by Sourcery
Automate the safe delivery of Dependabot updates while grouping and prioritizing pm toolchain releases.
New Features:
Enhancements:
Deployment:
Chores:
Summary by cubic
Automates Dependabot version bumps: npm is now checked daily, with
@unbrained/pm-cliandpm-*packages grouped into onepm-toolchainPR and the remaining minor/patch updates into onedependenciesPR. A new least-privilege workflow enables GitHub squash auto-merge inunbraindfor thepm-toolchaingroup and any update classified semver-minor or semver-patch, so eligible bumps land as soon as the required checks pass.Notes
testchecks, so a failing bump stays open as a real defect.dependabot/fetch-metadatacannot classify never auto-merges; only the explicit minor/patch orpm-toolchainallow-list passes.pm-toolchainuses calendar versions, so a year rollover (read as semver-major) still auto-merges; any other major update waits for a person.Written for commit a1c4c76. Summary will update on new commits.