EVOKORE// WORKFLOWS / dependabot-auto-merge.yml
Agent-33workflow · 59 lines
.github/workflows/dependabot-auto-merge.yml
CI / automation
View on GitHub →# REFERENCE-ONLY: GitHub Actions secrets referenced below are illustrative.
# Do not inject real credentials. See your CI/CD provider for proper secret management.
# Auto-approve and enable squash auto-merge for Dependabot PRs that are
# patch or minor version bumps. Major version bumps get a comment instead of
# an auto-merge so a human can review the breaking change.
#
# The job runs on `pull_request` (not `pull_request_target`) because the
# Dependabot updates touch lockfiles and metadata only — there is no need to
# read PR-author-controlled workflow code with elevated permissions.
name: Dependabot Auto-Merge
on:
pull_request:
types:
- opened
- synchronize
- reopened
permissions:
contents: write
pull-requests: write
jobs:
auto-merge:
name: Auto-merge patch and minor updates
runs-on: ubuntu-latest
if: github.actor == 'dependabot[bot]'
timeout-minutes: 10
steps:
- name: Fetch Dependabot metadata
id: metadata
uses: dependabot/fetch-metadata@v2
with:
github-token: '${{ secrets.GITHUB_TOKEN }}'
- name: Auto-approve patch and minor updates
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
run: gh pr review --approve "$PR_URL"
env:
PR_URL: ${{ github.event.pull_request.html_url }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Enable auto-merge for patch and minor updates
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
run: gh pr merge --auto --squash "$PR_URL"
env:
PR_URL: ${{ github.event.pull_request.html_url }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Flag major version bumps for manual review
if: steps.metadata.outputs.update-type == 'version-update:semver-major'
run: |
gh pr comment "$PR_URL" --body \
"This is a **major version** update (${{ steps.metadata.outputs.previous-version }} -> ${{ steps.metadata.outputs.new-version }}). Manual review required before merging."
env:
PR_URL: ${{ github.event.pull_request.html_url }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}