Skip to content

Auto-merge green Dependabot updates and group the pm toolchain into one daily PR - #129

Merged
unbraind merged 3 commits into
mainfrom
ci/auto-merge-green-dependabot-updates
Oct 4, 2026
Merged

unbraind merged 3 commits into
mainfrom
ci/auto-merge-green-dependabot-updates

Conversation

@unbraind

@unbraind unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

What

  • .github/dependabot.yml: npm is checked daily; @unbrained/pm-cli and pm-* packages arrive as one pm-toolchain PR, other minor/patch updates as one dependencies PR. Other ecosystems are unchanged.
  • .github/workflows/dependabot-auto-merge.yml: for Dependabot PRs only (and only in unbraind), dependabot/fetch-metadata (SHA-pinned v3.1.0) classifies the update; the pm-toolchain group (calendar-versioned, so a year rollover reads as semver-major) and every other non-major update get gh pr merge --auto --squash. Workflow default permissions are {}; the job alone gets contents: write + pull-requests: write.
  • Repository setting: auto-merge allowed, merged branches deleted.

Why

Fleet rule ([companion pm-cli-website-6d05]): a pm CLI release must reach every package without a hand-written certification PR. Branch protection still requires test (22), test (26), so nothing merges red; a bump that fails CI stays open as a real defect. Major updates still need a person. Same change as the reviewed pilot unbraind/pm-presets#118.

pm item

Summary by Sourcery

Automate the delivery of compatible Dependabot updates by grouping daily npm updates and enabling gated auto-merges for non-major changes.

New Features:

  • Enable automatic squash merging for eligible green Dependabot pull requests while leaving major and unclassified updates for manual review.

Enhancements:

  • Group the pm CLI toolchain into a single daily Dependabot update and consolidate other minor and patch npm updates into a separate daily pull request.
  • Apply least-privilege workflow permissions and restrict auto-merge behavior to Dependabot pull requests in the target repository.

Chores:

  • Enable repository auto-merge and merged-branch deletion settings.

Summary by cubic

Automates non-major Dependabot npm updates so green bumps merge themselves as soon as the required checks pass, letting a pm CLI release reach every package without a hand-written certification PR. Dependabot now checks npm daily: @unbrained/pm-cli and pm-* packages land as one pm-toolchain PR and other minor/patch updates as one dependencies PR.

  • The dependabot-auto-merge workflow enables GitHub squash auto-merge for pm-toolchain (calendar-versioned, so a year rollover reads as semver-major) and only for other updates classified minor or patch; unclassified or major updates stay open for human review. It runs with least-privilege permissions ({} default; the job alone gets contents: write and pull-requests: write).
  • The dependencies group is disjoint from pm-toolchain, so a pm package can never be bumped through it.
  • Branch protection still requires test (22) and test (26), so red bumps stay open as defects.
  • Requires the repository auto-merge setting to be enabled; merged branches are deleted.

Written for commit 47e972b. Summary will update on new commits.

Review in cubic

…ne daily PR

Version bumps of @unbrained/pm-cli, pm-ops and pm-changelog are mechanical.
Dependabot now checks npm daily and groups the pm toolchain (and other
minor/patch updates) into single pull requests; a least-privilege workflow
enables squash auto-merge for every non-major Dependabot PR, so it lands as
soon as the required checks pass and a failing bump stays open as a defect.

pm item: pm-context-h34i

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 15 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 40 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: b8407a31-987e-44fb-ba0c-29bc6c27696d
📥 Commits

Reviewing files that changed from the base of the PR and between 3da9317 and 47e972b.

📒 Files selected for processing (5)
  • .agents/pm/history/pm-context-h34i.jsonl
  • .agents/pm/tasks/pm-context-h34i.toon
  • .github/dependabot.yml
  • .github/workflows/dependabot-auto-merge.yml
  • CHANGELOG.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: dc9a42ab-d9c8-4450-83df-91fe4c9af904
📥 Commits

Reviewing files that changed from the base of the PR and between 3da9317 and c3e1d5f.

📒 Files selected for processing (5)
  • .agents/pm/history/pm-context-h34i.jsonl
  • .agents/pm/tasks/pm-context-h34i.toon
  • .github/dependabot.yml
  • .github/workflows/dependabot-auto-merge.yml
  • CHANGELOG.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • New Features
    • Dependabot checks for npm updates daily and groups toolchain updates separately from other dependencies.
    • Eligible Dependabot updates can be squash-merged automatically after required checks pass. Major updates outside the toolchain group are excluded.

Walkthrough

Dependabot npm checks now run daily and use separate toolchain and dependency groups. A new workflow enables squash auto-merge for qualifying Dependabot pull requests. The changelog and project records describe the rollout.

Changes

Dependabot rollout

Layer / File(s) Summary
Daily checks and update groups
.agents/pm/tasks/pm-context-h34i.toon, .github/dependabot.yml
The task record describes the update policy. Dependabot checks npm daily, groups @unbrained/pm-cli and pm-* as pm-toolchain, and limits the separate dependencies group to minor and patch updates.
Conditional auto-merge workflow
.github/workflows/dependabot-auto-merge.yml, CHANGELOG.md, .agents/pm/history/pm-context-h34i.jsonl
The workflow restricts its job to Dependabot pull requests in unbraind-owned repositories. It fetches dependency metadata and enables squash auto-merge for pm-toolchain updates or updates that are not semver-major. The changelog and task history record the rollout.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant GitHub
  participant Dependabot as Dependabot PR
  participant Workflow as dependabot-auto-merge.yml
  participant CLI as GitHub CLI
  GitHub->>Workflow: Trigger for a pull request
  Workflow->>Workflow: Check Dependabot actor and repository owner
  Workflow->>GitHub: Fetch dependency metadata
  GitHub-->>Workflow: Return dependency group and update type
  alt pm-toolchain group or non-major update
    Workflow->>CLI: Run gh pr merge --auto --squash
    CLI->>GitHub: Enable squash auto-merge
  else Other semver-major update
    Workflow->>Workflow: Skip merge command
  end
Loading

Merge Risk: ⚪ Minimal · up to c3e1d

No actionable merge-blocking issue is established. The configured grouping and auto-merge policy can proceed through normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to c3e1d

Bot-only eligibility, narrowly scoped permissions, and separation from dependency execution limit exposure. No new vulnerability was established, but required-check enforcement, effective token permissions, and handling of pending merge requests remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A compromised upstream package or action release could enter through an eligible Dependabot update, pass whatever merge controls are actually enforced, and reach main without a separate human merge decision. Npm dependency code can subsequently execute in the existing privileged release job. The immediate authority is repository-scoped; no organization-wide or cross-tenant privilege expansion is established.

Trust Boundaries and Controls

  • observed — The main controls are bot-authorship and organization checks, pinned metadata classification, job-scoped permissions, separate read-permission CI, and a main-only release gate. The release workflow comments describe branch protection as the merge authority and explain that its token cannot read the required-check configuration; those comments do not independently establish the current protection settings.

Resilience and Maintainability Implications

  • inferred — Classification precedes the merge command, and the workflow provides no fallback after metadata failure. An inability to obtain write authority would block this automation rather than broaden it. These fail-closed initiation properties do not establish cleanup or revalidation of a request that was already enabled.

Hardening Proposals

  • proposed — Confirm that main requires the intended test contexts and that relevant bypass rules cannot defeat the green-only policy. Separately confirm the effective token permissions for Dependabot-triggered runs rather than relying on declared permissions alone.
  • proposed — Establish GitHub's pending-auto-merge behavior across subsequent commits, changed eligibility, repetition, and cancellation. Add explicit revocation or recovery only if platform behavior does not preserve the intended authorization invariant.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main changes: automatic merging of green Dependabot updates and daily grouping of the pm toolchain.
Description check ✅ Passed The description explains the Dependabot schedule and groups, auto-merge workflow, permissions, and safety requirements. It is directly related to the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR changes npm Dependabot updates to run daily with separate PM toolchain and general dependency grouping, then adds a narrowly scoped, SHA-pinned workflow that enables squash auto-merge for green Dependabot updates while treating calendar-versioned PM releases as eligible even when classified as semver-major. It also records the associated PM task metadata.

Flow diagram for Dependabot update grouping and auto-merge

flowchart TD
    A[Daily npm Dependabot scan] --> B{Update matches pm-toolchain?}
    B -->|Yes| C[Create pm-toolchain PR]
    B -->|No| D[Create dependencies PR for minor or patch]
    C --> E[Dependabot auto-merge workflow]
    D --> E
    E --> F{Dependabot PR in unbraind?}
    F -->|No| G[No auto-merge]
    F -->|Yes| H[Fetch Dependabot metadata]
    H --> I{PM toolchain or non-major update?}
    I -->|Yes| J[Enable squash auto-merge]
    I -->|No| G
    J --> K{Required checks pass}
    K -->|Yes| L[Merge PR]
    K -->|No| M[Keep PR open]
Loading

File-Level Changes

Change Details Files
Configure daily npm update cadence and consolidate package updates into targeted Dependabot groups.
  • Run npm updates daily.
  • Group the PM CLI and pm-prefixed packages into a dedicated toolchain PR.
  • Group non-PM minor and patch updates separately while excluding major updates.
.github/dependabot.yml
Add a least-privilege workflow that enables squash auto-merge for eligible Dependabot pull requests.
  • Restrict execution to Dependabot PRs in the unbraind organization.
  • Use SHA-pinned Dependabot metadata fetching to identify groups and update severity.
  • Auto-merge the pm-toolchain group and all non-major updates after required checks pass.
  • Grant write permissions only at the job level and invoke GitHub CLI auto-merge.
.github/workflows/dependabot-auto-merge.yml
Record the associated PM task and history entries.
  • Add the task definition and JSONL history records for the change.
.agents/pm/tasks/pm-context-h34i.toon
.agents/pm/history/pm-context-h34i.jsonl

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@greptile-apps

greptile-apps Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Enables automatic merging of dependency updates via GitHub workflow.

The changes since the last review appear safe to merge.

What we checked:

  • Unknown updates stay manual: The changed condition accepts only minor or patch updates outside pm-toolchain. An empty or unknown update-type matches neither.
  • Pm packages stay together: dependencies excludes the same package patterns that pm-toolchain includes.

Summary

This PR groups daily npm updates and enables squash auto-merge for eligible Dependabot PRs.

  • The latest changes explicitly select all other npm packages while excluding the pm toolchain.
  • Auto-merge now requires a minor or patch classification, except for the intentional pm-toolchain exception.
  • Task records now describe that exception and the job’s write permissions.
  • No actionable new issues were found. No previous review threads were supplied.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart TD
  A[Dependabot PR] --> B{Dependabot author and expected owner?}
  B -- No --> C[Skip]
  B -- Yes --> D[Read update metadata]
  D --> E{pm-toolchain or minor or patch?}
  E -- No --> F[Leave for manual review]
  E -- Yes --> G[Enable squash auto-merge]
  G --> H[GitHub waits for required checks]
  H --> I[Merge when allowed]
Loading

Reviews (3) · Last reviewed commit: "Allow-list minor and patch updates and d..."

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai full review
@greptileai review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

…sions

Review feedback: an update that fetch-metadata cannot classify must not
auto-merge, so the condition now requires semver-minor or semver-patch
outside the calendar-versioned pm-toolchain group. The job's write scopes
are documented, the dependencies group selects every package explicitly,
and the item's acceptance criteria name the pm-toolchain exception.

pm item: pm-context-h34i
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai full review
@greptileai review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 40 minutes.

@unbraind
unbraind merged commit 438cb2b into main Oct 4, 2026
13 checks passed
@unbraind
unbraind deleted the ci/auto-merge-green-dependabot-updates branch October 4, 2026 18:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant