Repository navigation
Auto-merge green Dependabot updates and group the pm toolchain into one daily PR - #129
Conversation
…ne daily PR Version bumps of @unbrained/pm-cli, pm-ops and pm-changelog are mechanical. Dependabot now checks npm daily and groups the pm toolchain (and other minor/patch updates) into single pull requests; a least-privilege workflow enables squash auto-merge for every non-major Dependabot PR, so it lands as soon as the required checks pass and a failing bump stays open as a defect. pm item: pm-context-h34i
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 40 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (5)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (5)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Summary by CodeRabbit
WalkthroughDependabot npm checks now run daily and use separate toolchain and dependency groups. A new workflow enables squash auto-merge for qualifying Dependabot pull requests. The changelog and project records describe the rollout. ChangesDependabot rollout
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant GitHub
participant Dependabot as Dependabot PR
participant Workflow as dependabot-auto-merge.yml
participant CLI as GitHub CLI
GitHub->>Workflow: Trigger for a pull request
Workflow->>Workflow: Check Dependabot actor and repository owner
Workflow->>GitHub: Fetch dependency metadata
GitHub-->>Workflow: Return dependency group and update type
alt pm-toolchain group or non-major update
Workflow->>CLI: Run gh pr merge --auto --squash
CLI->>GitHub: Enable squash auto-merge
else Other semver-major update
Workflow->>Workflow: Skip merge command
end
Merge Risk: ⚪ Minimal · up to No actionable merge-blocking issue is established. The configured grouping and auto-merge policy can proceed through normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Bot-only eligibility, narrowly scoped permissions, and separation from dependency execution limit exposure. No new vulnerability was established, but required-check enforcement, effective token permissions, and handling of pending merge requests remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideThis PR changes npm Dependabot updates to run daily with separate PM toolchain and general dependency grouping, then adds a narrowly scoped, SHA-pinned workflow that enables squash auto-merge for green Dependabot updates while treating calendar-versioned PM releases as eligible even when classified as semver-major. It also records the associated PM task metadata. Flow diagram for Dependabot update grouping and auto-mergeflowchart TD
A[Daily npm Dependabot scan] --> B{Update matches pm-toolchain?}
B -->|Yes| C[Create pm-toolchain PR]
B -->|No| D[Create dependencies PR for minor or patch]
C --> E[Dependabot auto-merge workflow]
D --> E
E --> F{Dependabot PR in unbraind?}
F -->|No| G[No auto-merge]
F -->|Yes| H[Fetch Dependabot metadata]
H --> I{PM toolchain or non-major update?}
I -->|Yes| J[Enable squash auto-merge]
I -->|No| G
J --> K{Required checks pass}
K -->|Yes| L[Merge PR]
K -->|No| M[Keep PR open]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
pm item: pm-context-h34i
|
@coderabbitai full review |
✅ Action performedFull review finished. |
…sions Review feedback: an update that fetch-metadata cannot classify must not auto-merge, so the condition now requires semver-minor or semver-patch outside the calendar-versioned pm-toolchain group. The job's write scopes are documented, the dependencies group selects every package explicitly, and the item's acceptance criteria name the pm-toolchain exception. pm item: pm-context-h34i
|
@coderabbitai full review |
|
What
.github/dependabot.yml: npm is checked daily;@unbrained/pm-cliandpm-*packages arrive as onepm-toolchainPR, other minor/patch updates as onedependenciesPR. Other ecosystems are unchanged..github/workflows/dependabot-auto-merge.yml: for Dependabot PRs only (and only inunbraind),dependabot/fetch-metadata(SHA-pinned v3.1.0) classifies the update; thepm-toolchaingroup (calendar-versioned, so a year rollover reads as semver-major) and every other non-major update getgh pr merge --auto --squash. Workflow default permissions are{}; the job alone getscontents: write+pull-requests: write.Why
Fleet rule ([companion pm-cli-website-6d05]): a pm CLI release must reach every package without a hand-written certification PR. Branch protection still requires
test (22),test (26), so nothing merges red; a bump that fails CI stays open as a real defect. Major updates still need a person. Same change as the reviewed pilot unbraind/pm-presets#118.pm item
Summary by Sourcery
Automate the delivery of compatible Dependabot updates by grouping daily npm updates and enabling gated auto-merges for non-major changes.
New Features:
Enhancements:
Chores:
Summary by cubic
Automates non-major Dependabot npm updates so green bumps merge themselves as soon as the required checks pass, letting a pm CLI release reach every package without a hand-written certification PR. Dependabot now checks npm daily:
@unbrained/pm-cliandpm-*packages land as onepm-toolchainPR and other minor/patch updates as onedependenciesPR.dependabot-auto-mergeworkflow enables GitHub squash auto-merge forpm-toolchain(calendar-versioned, so a year rollover reads as semver-major) and only for other updates classified minor or patch; unclassified or major updates stay open for human review. It runs with least-privilege permissions ({}default; the job alone getscontents: writeandpull-requests: write).dependenciesgroup is disjoint frompm-toolchain, so a pm package can never be bumped through it.test (22)andtest (26), so red bumps stay open as defects.Written for commit 47e972b. Summary will update on new commits.