Skip to content

Auto-merge green Dependabot updates and group the pm toolchain into one daily PR - #143

Merged
unbraind merged 3 commits into
mainfrom
ci/auto-merge-green-dependabot-updates
Oct 4, 2026
Merged

unbraind merged 3 commits into
mainfrom
ci/auto-merge-green-dependabot-updates

Conversation

@unbraind

@unbraind unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

What

  • .github/dependabot.yml: npm is checked daily; @unbrained/pm-cli and pm-* packages arrive as one pm-toolchain PR, other minor/patch updates as one dependencies PR. Other ecosystems are unchanged.
  • .github/workflows/dependabot-auto-merge.yml: for Dependabot PRs only (and only in unbraind), dependabot/fetch-metadata (SHA-pinned v3.1.0) classifies the update; the pm-toolchain group (calendar-versioned, so a year rollover reads as semver-major) and every other non-major update get gh pr merge --auto --squash. Workflow default permissions are {}; the job alone gets contents: write + pull-requests: write.
  • Repository setting: auto-merge allowed, merged branches deleted.

Why

Fleet rule ([companion pm-cli-website-6d05]): a pm CLI release must reach every package without a hand-written certification PR. Branch protection still requires test (22), test (26), so nothing merges red; a bump that fails CI stays open as a real defect. Major updates still need a person. Same change as the reviewed pilot unbraind/pm-presets#118.

pm item

Summary by Sourcery

Automate the safe delivery of Dependabot updates while grouping and prioritizing pm toolchain releases.

New Features:

  • Configure daily npm Dependabot updates with grouped pull requests for the pm toolchain and other minor or patch dependencies.
  • Automatically enable squash auto-merge for eligible green Dependabot updates while leaving other major updates for manual review.

Enhancements:

  • Apply least-privilege permissions to the Dependabot auto-merge workflow and preserve required status checks as merge gates.

Deployment:

  • Enable repository auto-merge and automatic deletion of merged branches.

Chores:

  • Record the change in the changelog and project task history.

Summary by cubic

Automates Dependabot version bumps: npm is now checked daily, with @unbrained/pm-cli and pm-* packages grouped into one pm-toolchain PR and the remaining minor/patch updates into one dependencies PR. A new least-privilege workflow enables GitHub squash auto-merge in unbraind for the pm-toolchain group and any update classified semver-minor or semver-patch, so eligible bumps land as soon as the required checks pass.

Notes

  • Branch protection still requires the test checks, so a failing bump stays open as a real defect.
  • An update dependabot/fetch-metadata cannot classify never auto-merges; only the explicit minor/patch or pm-toolchain allow-list passes.
  • pm-toolchain uses calendar versions, so a year rollover (read as semver-major) still auto-merges; any other major update waits for a person.
  • Mirrors the reviewed pilot Auto-merge green Dependabot updates and group the pm toolchain into one daily PR pm-presets#118.

Written for commit a1c4c76. Summary will update on new commits.

Review in cubic

…ne daily PR

Version bumps of @unbrained/pm-cli, pm-ops and pm-changelog are mechanical.
Dependabot now checks npm daily and groups the pm toolchain (and other
minor/patch updates) into single pull requests; a least-privilege workflow
enables squash auto-merge for every non-major Dependabot PR, so it lands as
soon as the required checks pass and a failing bump stays open as a defect.

pm item: ops-k1lf

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 15 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 40 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 0e1dffbd-bbd9-42d2-9557-bcd806958080
📥 Commits

Reviewing files that changed from the base of the PR and between d79c9bd and a1c4c76.

📒 Files selected for processing (6)
  • .agents/pm/history/_workspace.jsonl
  • .agents/pm/history/ops-k1lf.jsonl
  • .agents/pm/tasks/ops-k1lf.toon
  • .github/dependabot.yml
  • .github/workflows/dependabot-auto-merge.yml
  • CHANGELOG.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: f8b76ee3-ce6d-4e3c-a8ae-204437cb7096
📥 Commits

Reviewing files that changed from the base of the PR and between d79c9bd and d1833dd.

📒 Files selected for processing (6)
  • .agents/pm/history/_workspace.jsonl
  • .agents/pm/history/ops-k1lf.jsonl
  • .agents/pm/tasks/ops-k1lf.toon
  • .github/dependabot.yml
  • .github/workflows/dependabot-auto-merge.yml
  • CHANGELOG.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • New Features
    • Dependency updates are now checked daily, with toolchain updates grouped separately from other dependencies.
    • Eligible Dependabot updates are automatically squash-merged after required checks pass. Non-major updates qualify, along with updates in the toolchain group.

Walkthrough

Dependabot npm checks now run daily and group toolchain updates separately from minor and patch dependency updates. A new pull-request workflow enables squash auto-merge for toolchain or non-major updates. Task records and the changelog document the automation and rollout.

Changes

Dependabot automation

Layer / File(s) Summary
Daily update grouping
.github/dependabot.yml
The npm schedule changes from weekly to daily. Dependabot groups @unbrained/pm-cli and pm-* updates as pm-toolchain. The dependencies group excludes those packages and includes minor and patch updates.
Auto-merge and rollout records
.github/workflows/dependabot-auto-merge.yml, .agents/pm/tasks/ops-k1lf.toon, .agents/pm/history/ops-k1lf.jsonl, .agents/pm/history/_workspace.jsonl, CHANGELOG.md
The workflow fetches dependency metadata and enables squash auto-merge for pm-toolchain updates or non-major updates. Task and history records capture the requirements and rollout. The changelog describes the daily grouping and auto-merge behavior.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant Dependabot
  participant GitHubActions
  participant DependabotPR
  participant GHCli
  Dependabot->>DependabotPR: Create grouped update pull request
  DependabotPR->>GitHubActions: Trigger pull-request workflow
  GitHubActions->>DependabotPR: Fetch dependency metadata
  GitHubActions->>GHCli: Run auto-merge for pm-toolchain or non-major update
  GHCli->>DependabotPR: Enable squash auto-merge
Loading

Merge Risk: ⚪ Minimal · up to d1833

No concrete merge-blocking defect is established. Confirm that repository settings require both test checks before relying on green-only auto-merge.

Security Architecture Review

Security architecture risk: 🔵 Low · up to d1833

The automation is narrowly restricted and does not execute pull-request code with its write token. However, faster unattended dependency adoption increases supply-chain exposure, and the required-check settings could not be verified. The review does not establish that failing updates can merge.

Retained concerns

  • Low · security · inferred: Daily updates and the new unattended merge-request path shorten the opportunity to detect a compromised eligible release before adoption. Passing functional checks does not establish that a dependency is benign. The absence of cooldown predates this PR; the concern is increased adoption exposure, not a newly removed delay or a proven exploit.
  • Low · security · inferred: The claimed green-only merge invariant depends on effective GitHub protection settings, not merely the presence of CI jobs. Whether both intended test checks are mandatory for applicable target branches, without an applicable bypass, remains unresolved. Missing settings evidence does not demonstrate a protection failure.
Security review details

Security Blast Radius

  • inferred — The evidenced authority is repository-local PR merge authority. An eligible upstream dependency compromise can affect the repository's dependency graph or workflows through a Dependabot PR, including grouped updates. No supplied evidence establishes production credentials, cross-repository write authority, or fleet-wide propagation.

Security Findings and Attack Paths

  • inferred — The relevant supply-chain path is an attacker-controlled upstream release becoming an eligible Dependabot update and satisfying whatever merge prerequisites actually apply. Ordinary PR authors do not satisfy the identity guard. The retained finding remains reportable, but its supplied payload does not establish a successful malicious release or a more specific exploit. The merge-gating candidate remains deferred because protection settings are unavailable.

Trust Boundaries and Controls

  • observed — The privileged job has declared contents and pull-request write permissions, while workflow defaults grant none. It uses a pinned metadata action and a quoted event PR URL, and contains no checkout, npm install, or execution of PR code. These controls separate the merge token from dependency execution in CI.

Resilience and Maintainability Implications

  • inferred — Eligibility evaluation and the merge request are separate operations, without an explicit head-SHA binding, recovery, or cancellation step. GitHub owns the subsequent lifecycle. Missing runtime evidence leaves effective permissions, repetition, concurrent head changes, failed requests, and pending-state recovery unresolved; the source alone does not prove an unsafe transition.

Hardening Proposals

  • proposed — Before relying on unattended merging, verify effective required-check, approval, and bypass settings for applicable target branches. Validate a representative Dependabot PR through failed checks, head updates, repeated events, and successful merge, and establish how pending auto-merge requests are canceled during rollback.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main changes: daily Dependabot grouping and automatic merging of eligible updates.
Description check ✅ Passed The description explains the Dependabot schedule and grouping, auto-merge rules, required checks, and related task.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR changes npm Dependabot checks to daily grouped updates and adds a narrowly scoped workflow that enables squash auto-merge for green Dependabot PRs. The pm-toolchain group is treated as an exception to the normal semver-major hold because calendar-versioned year rollovers must propagate automatically, while repository settings permit auto-merge and delete merged branches.

Sequence diagram for Dependabot auto-merge workflow

sequenceDiagram
    participant Dependabot
    participant GitHubActions
    participant Metadata
    participant GitHub
    participant BranchProtection

    Dependabot->>GitHub: Open or update pull request
    GitHub->>GitHubActions: pull_request event
    GitHubActions->>Metadata: dependabot/fetch-metadata
    Metadata-->>GitHubActions: dependency-group and update-type
    alt pm-toolchain group
        GitHubActions->>GitHub: gh pr merge --auto --squash
    else non-major update
        GitHubActions->>GitHub: gh pr merge --auto --squash
    else other major update
        GitHubActions-->>GitHub: No auto-merge
    end
    GitHub->>BranchProtection: Check test (22) and test (26)
    BranchProtection-->>GitHub: Allow merge when checks pass
Loading

File-Level Changes

Change Details Files
Configure Dependabot to run daily and consolidate npm updates into toolchain and general dependency PRs.
  • Schedule npm checks daily.
  • Group @unbrained/pm-cli and pm-* packages into pm-toolchain.
  • Group all other minor and patch updates into dependencies while excluding toolchain packages.
  • Leave other ecosystem configurations unchanged.
.github/dependabot.yml
Automatically enable squash auto-merge for eligible green Dependabot pull requests with narrowly scoped permissions.
  • Restrict execution to Dependabot PRs in the unbraind organization.
  • Pin dependabot/fetch-metadata to the v3.1.0 commit.
  • Auto-merge the pm-toolchain group and all non-major updates; leave unrelated major updates for manual review.
  • Set workflow-wide permissions to none and grant only contents and pull-request write access to the job.
  • Rely on branch protection checks to prevent failing updates from merging.
.github/workflows/dependabot-auto-merge.yml
Record the associated pm task and history artifacts.
  • Add the ops-k1lf task definition.
  • Add its JSONL history entry.
.agents/pm/tasks/ops-k1lf.toon
.agents/pm/history/ops-k1lf.jsonl

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@greptile-apps

greptile-apps Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Enables automatic merging of dependency updates via GitHub workflow.

The reviewed changes appear safe to merge; no new blocking issue was found.

Summary

Checks npm dependencies daily and separates pm toolchain updates from other minor/patch updates. The new workflow requests squash auto-merge for eligible Dependabot PRs.

  • The latest changes explicitly match other dependencies with patterns: ["*"].
  • Updates outside pm-toolchain must be classified as minor or patch.
  • Task records now describe the calendar-version exception and updated merge rules.
  • No new actionable issues were found.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart TD
  A[Pull request event] --> B{Dependabot author and unbraind owner?}
  B -->|No| C[Skip job]
  B -->|Yes| D[Read update metadata]
  D --> E{pm-toolchain or classified minor or patch?}
  E -->|No| F[Leave for manual review]
  E -->|Yes| G[Request squash auto-merge]
  G --> H[GitHub applies repository merge requirements]
Loading

Reviews (3) · Last reviewed commit: "Allow-list minor and patch updates and d..."

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai full review
@greptileai review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

…sions

Review feedback: an update that fetch-metadata cannot classify must not
auto-merge, so the condition now requires semver-minor or semver-patch
outside the calendar-versioned pm-toolchain group. The job's write scopes
are documented, the dependencies group selects every package explicitly,
and the item's acceptance criteria name the pm-toolchain exception.

pm item: ops-k1lf
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai full review
@greptileai review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 40 minutes.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Rate Limit Exceeded

@unbraind have exceeded the limit for the number of chat messages per hour. Please wait 51 minutes and 45 seconds before sending another message.

@unbraind
unbraind merged commit 6cf6111 into main Oct 4, 2026
10 checks passed
@unbraind
unbraind deleted the ci/auto-merge-green-dependabot-updates branch October 4, 2026 18:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant