Skip to content

Commit 11df56c

Browse files
committed
Switch auto-merge to workflow_run trigger (no branch protection needed)
Instead of pull_request_target + --auto (which requires branch protection and the "Allow auto-merge" repo setting), trigger on workflow_run after the Test workflow succeeds. This merges directly once tests pass, with no repo settings required. Security: workflow_run always runs base branch code, never checks out PR code, and the PR author is verified both via the event actor and a redundant API check. https://claude.ai/code/session_01UWiK5bH6Be6vft43zVVNbH
1 parent 98ea6a3 commit 11df56c

1 file changed

Lines changed: 20 additions & 10 deletions

File tree

Lines changed: 20 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,23 +1,33 @@
11
name: Auto-merge Dependabot PRs
22

3-
on: pull_request_target
3+
on:
4+
workflow_run:
5+
workflows: ["Test"]
6+
types: [completed]
47

58
permissions:
69
contents: write
710
pull-requests: write
811

912
jobs:
1013
auto-merge:
11-
if: github.event.pull_request.user.login == 'dependabot[bot]'
14+
if: >-
15+
github.event.workflow_run.event == 'pull_request' &&
16+
github.event.workflow_run.conclusion == 'success' &&
17+
github.event.workflow_run.actor.login == 'dependabot[bot]'
1218
runs-on: ubuntu-latest
1319
steps:
14-
- name: Approve PR
15-
run: gh pr review --approve "$PR_URL"
20+
- name: Find and merge Dependabot PR
1621
env:
17-
PR_URL: ${{ github.event.pull_request.html_url }}
18-
GH_TOKEN: ${{ github.token }}
19-
- name: Enable auto-merge
20-
run: gh pr merge --auto --squash "$PR_URL"
21-
env:
22-
PR_URL: ${{ github.event.pull_request.html_url }}
2322
GH_TOKEN: ${{ github.token }}
23+
REPO: ${{ github.repository }}
24+
HEAD_SHA: ${{ github.event.workflow_run.head_sha }}
25+
run: |
26+
pr_number=$(gh api "repos/$REPO/commits/$HEAD_SHA/pulls" \
27+
--jq 'map(select(.user.login == "dependabot[bot]")) | .[0].number')
28+
if [ -z "$pr_number" ] || [ "$pr_number" = "null" ]; then
29+
echo "No Dependabot PR found for SHA $HEAD_SHA"
30+
exit 0
31+
fi
32+
gh pr review --approve "$pr_number" -R "$REPO"
33+
gh pr merge --squash "$pr_number" -R "$REPO"

0 commit comments

Comments
 (0)