diff --git a/.agents/pm/history/pm-context-h34i.jsonl b/.agents/pm/history/pm-context-h34i.jsonl new file mode 100644 index 0000000..1b50947 --- /dev/null +++ b/.agents/pm/history/pm-context-h34i.jsonl @@ -0,0 +1,7 @@ +{"hash_algorithm":"sha256","ts":"2026-10-04T16:54:19.945Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"create","patch":[{"op":"replace","path":"/body","value":"Fleet-wide automation of version bumps; see companion pm-cli-website-6d05."},{"op":"add","path":"/metadata/id","value":"pm-context-h34i"},{"op":"add","path":"/metadata/title","value":"Auto-merge green Dependabot updates and group the pm toolchain into one daily PR"},{"op":"add","path":"/metadata/description","value":"Version bumps of the pm CLI, SDK-bearing packages and fleet gates are mechanical and must land without a hand-written certification PR. Dependabot checks npm daily, groups @unbrained/pm-cli and pm-* packages into one pm-toolchain PR and other minor/patch updates into one dependencies PR; a least-privilege workflow enables GitHub squash auto-merge for every non-major Dependabot PR so it merges as soon as the required checks pass. A failing bump is a real defect to fix. Fleet rule: companion pm-cli-website-6d05; pilot unbraind/pm-presets#118."},{"op":"add","path":"/metadata/type","value":"Task"},{"op":"add","path":"/metadata/status","value":"open"},{"op":"add","path":"/metadata/priority","value":2},{"op":"add","path":"/metadata/tags","value":["automation","ci","dependencies"]},{"op":"add","path":"/metadata/created_at","value":"2026-10-04T16:54:19.945Z"},{"op":"add","path":"/metadata/updated_at","value":"2026-10-04T16:54:19.945Z"},{"op":"add","path":"/metadata/deadline","value":"2026-10-06T00:00:00.000Z"},{"op":"add","path":"/metadata/assignee","value":"claude-orchestrator"},{"op":"add","path":"/metadata/author","value":"claude-orchestrator"},{"op":"add","path":"/metadata/estimated_minutes","value":15},{"op":"add","path":"/metadata/acceptance_criteria","value":"dependabot.yml checks npm daily with pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge only for Dependabot non-major updates with least-privilege permissions; repository allows auto-merge; required checks still gate every merge"},{"op":"add","path":"/metadata/comments","value":[{"created_at":"2026-10-04T16:54:19.945Z","author":"claude-orchestrator","text":"Rolled out from the reviewed pilot unbraind/pm-presets#118."}]},{"op":"add","path":"/metadata/files","value":[{"path":".github/dependabot.yml","scope":"project"},{"path":".github/workflows/dependabot-auto-merge.yml","scope":"project"}]},{"op":"add","path":"/metadata/docs","value":[{"path":".github/workflows/dependabot-auto-merge.yml","scope":"project"}]}],"before_hash":"3cc22dff72be7b14824654a7a64ea62b04799939b2fee54c1b5f52ca60bf6df0","after_hash":"18f430392952983034e7b2c36b30a6b767f653909d756dde74728cc7fa035a47","item_hash_version":3,"message":"Create item for Dependabot auto-merge | explicit_unset=dependencies,learnings,notes,tests","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"cbbd54e6a87973157849d6a401062b049d1592f6e20c9dc37e3de82754032bd9"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:54:20.646Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"claim","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:54:20.646Z"},{"op":"add","path":"/metadata/claim_principal","value":"claude-orchestrator"}],"before_hash":"18f430392952983034e7b2c36b30a6b767f653909d756dde74728cc7fa035a47","after_hash":"4941058d7817f5bb5269dc535f7b4ddd461d88b276bd903e8e6c1f0ea98f2195","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"962e69704083464ee6105d1936d8bb8e727b28dc9636d0f758c72673b07a4b07"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:54:21.331Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:54:21.331Z"},{"op":"replace","path":"/metadata/status","value":"in_progress"}],"before_hash":"4941058d7817f5bb5269dc535f7b4ddd461d88b276bd903e8e6c1f0ea98f2195","after_hash":"a68e52721516f8080b0d3249aedf5d163d682bdb1ae05095c9a3e5e8a8a1c3ca","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"41c3eda19881f702219bd0daf409186a290b515b31c927181b9690abd9b56faf"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:58:39.003Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"close","patch":[{"op":"remove","path":"/metadata/assignee"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:58:39.003Z"},{"op":"replace","path":"/metadata/status","value":"closed"},{"op":"add","path":"/metadata/closed_at","value":"2026-10-04T16:58:38.695Z"},{"op":"add","path":"/metadata/completed_at","value":"2026-10-04T16:58:38.695Z"},{"op":"add","path":"/metadata/close_reason","value":"Rolled out the reviewed pilot (unbraind/pm-presets#118, auto-merge proven on pm-presets#119, groups made disjoint in pm-presets#120). This PR's required checks gate the merge; repository auto-merge and branch deletion enabled."}],"before_hash":"a68e52721516f8080b0d3249aedf5d163d682bdb1ae05095c9a3e5e8a8a1c3ca","after_hash":"f4ffbdff1005d360ac231fb85dad4002133a18e817d41fdfaf38266fab679149","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"eda26648703590bc2aef947075148bddd372c00cb3c6063377ba435eaec64531"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:58:46.312Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"release","patch":[{"op":"remove","path":"/metadata/claim_principal"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:58:46.312Z"}],"before_hash":"f4ffbdff1005d360ac231fb85dad4002133a18e817d41fdfaf38266fab679149","after_hash":"ffa3937356b905ea8271cdc5a850c0d3160f976765684dc51306ca6d619c3d81","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"6127b3b40a92c479227ef4bd1c4e266603c227fc807ab0500f4d2b5143e35da7"} +{"hash_algorithm":"sha256","ts":"2026-10-04T17:20:35.030Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"update","patch":[{"op":"replace","path":"/metadata/acceptance_criteria","value":"dependabot.yml checks npm daily with disjoint pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge for the calendar-versioned pm-toolchain group (year rollovers read as semver-major) and otherwise only for updates classified minor or patch, with documented least-privilege permissions; repository allows auto-merge; required checks still gate every merge"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T17:20:35.030Z"}],"before_hash":"ffa3937356b905ea8271cdc5a850c0d3160f976765684dc51306ca6d619c3d81","after_hash":"6b2a6247a2798b0589daf7e2983cf66fb5c5a3b994cbf32cdcc548d9a0d2dfb8","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"4091361b6f718e6a987c926f24fe03c6d8b98f92a574ca0553717c999f38314d"} +{"hash_algorithm":"sha256","ts":"2026-10-04T17:20:41.728Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":null,"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"comment_add","patch":[{"op":"add","path":"/metadata/comments/1","value":{"created_at":"2026-10-04T17:20:41.728Z","author":"claude-orchestrator","text":"Review round 2 (Greptile/CodeRabbit across the fleet rollout): explicit minor/patch allow-list so an unclassified update never auto-merges; documented why the job needs write permissions; explicit patterns for the dependencies group; acceptance criteria now name the pm-toolchain calendar-version exception. Refused: switching to pull_request_target (GitHub keeps Dependabot-authored runs read-only there too; the pull_request + permissions pattern is proven by pm-presets#119) and removing the pm-toolchain exception (owner rule pm-cli-website-6d05: pm bumps land unattended; required checks gate them)."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T17:20:41.728Z"}],"before_hash":"6b2a6247a2798b0589daf7e2983cf66fb5c5a3b994cbf32cdcc548d9a0d2dfb8","after_hash":"63e56121b8e4cdfea6bdc7f685774d88f626005454fa31f8a163913f3935556e","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"c31249d660f59507f3f7a1b280500ba324f506a9dbbfb06a5910e84a3620e340"} diff --git a/.agents/pm/tasks/pm-context-h34i.toon b/.agents/pm/tasks/pm-context-h34i.toon new file mode 100644 index 0000000..d94d4e5 --- /dev/null +++ b/.agents/pm/tasks/pm-context-h34i.toon @@ -0,0 +1,25 @@ +id: pm-context-h34i +title: Auto-merge green Dependabot updates and group the pm toolchain into one daily PR +description: "Version bumps of the pm CLI, SDK-bearing packages and fleet gates are mechanical and must land without a hand-written certification PR. Dependabot checks npm daily, groups @unbrained/pm-cli and pm-* packages into one pm-toolchain PR and other minor/patch updates into one dependencies PR; a least-privilege workflow enables GitHub squash auto-merge for every non-major Dependabot PR so it merges as soon as the required checks pass. A failing bump is a real defect to fix. Fleet rule: companion pm-cli-website-6d05; pilot unbraind/pm-presets#118." +type: Task +status: closed +priority: 2 +tags[3]: automation,ci,dependencies +created_at: "2026-10-04T16:54:19.945Z" +updated_at: "2026-10-04T17:20:41.728Z" +deadline: "2026-10-06T00:00:00.000Z" +closed_at: "2026-10-04T16:58:38.695Z" +completed_at: "2026-10-04T16:58:38.695Z" +author: claude-orchestrator +estimated_minutes: 15 +acceptance_criteria: "dependabot.yml checks npm daily with disjoint pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge for the calendar-versioned pm-toolchain group (year rollovers read as semver-major) and otherwise only for updates classified minor or patch, with documented least-privilege permissions; repository allows auto-merge; required checks still gate every merge" +comments[2]{created_at,author,text}: + "2026-10-04T16:54:19.945Z",claude-orchestrator,Rolled out from the reviewed pilot unbraind/pm-presets#118. + "2026-10-04T17:20:41.728Z",claude-orchestrator,"Review round 2 (Greptile/CodeRabbit across the fleet rollout): explicit minor/patch allow-list so an unclassified update never auto-merges; documented why the job needs write permissions; explicit patterns for the dependencies group; acceptance criteria now name the pm-toolchain calendar-version exception. Refused: switching to pull_request_target (GitHub keeps Dependabot-authored runs read-only there too; the pull_request + permissions pattern is proven by pm-presets#119) and removing the pm-toolchain exception (owner rule pm-cli-website-6d05: pm bumps land unattended; required checks gate them)." +files[2]{path,scope}: + .github/dependabot.yml,project + .github/workflows/dependabot-auto-merge.yml,project +docs[1]{path,scope}: + .github/workflows/dependabot-auto-merge.yml,project +close_reason: "Rolled out the reviewed pilot (unbraind/pm-presets#118, auto-merge proven on pm-presets#119, groups made disjoint in pm-presets#120). This PR's required checks gate the merge; repository auto-merge and branch deletion enabled." +body: Fleet-wide automation of version bumps; see companion pm-cli-website-6d05. diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 35d995d..82f0b16 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -3,8 +3,29 @@ updates: - package-ecosystem: "npm" directory: "/" schedule: - interval: "weekly" + interval: "daily" open-pull-requests-limit: 5 + groups: + # The pm CLI, its SDK-bearing packages and the fleet gates move together + # in one pull request per day; dependabot-auto-merge.yml merges it as soon + # as the required checks pass, so a release bump needs no manual work. + # No update-types filter: pm uses calendar versions, so a year rollover + # (2026.x -> 2027.x) is a semver major that must still land unattended. + pm-toolchain: + patterns: + - "@unbrained/pm-cli" + - "pm-*" + dependencies: + # Every other npm dependency, disjoint from pm-toolchain, so a pm + # package can never be bumped here (and capped by update-types). + patterns: + - "*" + exclude-patterns: + - "@unbrained/pm-cli" + - "pm-*" + update-types: + - "minor" + - "patch" - package-ecosystem: "github-actions" directory: "/" diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml new file mode 100644 index 0000000..85d4c77 --- /dev/null +++ b/.github/workflows/dependabot-auto-merge.yml @@ -0,0 +1,33 @@ +name: dependabot-auto-merge + +# Version bumps are mechanical: every non-major Dependabot pull request gets +# GitHub auto-merge, so it lands the moment the required checks pass. Branch +# protection still gates the merge; a failing bump stays open as a defect. +on: pull_request + +permissions: {} + +jobs: + enable-auto-merge: + if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository_owner == 'unbraind' + runs-on: ubuntu-latest + # `gh pr merge --auto` needs pull-requests: write to enable auto-merge + # and contents: write for the squash merge GitHub performs once the + # required checks pass. Nothing is checked out or executed from the PR. + permissions: + contents: write + pull-requests: write + steps: + - id: metadata + uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 + # pm-toolchain is calendar-versioned (a new year reads as semver-major), + # so it always auto-merges. Anything else must be classified minor or + # patch; a major or unclassified update waits for a person. + - if: >- + steps.metadata.outputs.dependency-group == 'pm-toolchain' || + steps.metadata.outputs.update-type == 'version-update:semver-minor' || + steps.metadata.outputs.update-type == 'version-update:semver-patch' + run: gh pr merge --auto --squash "$PR_URL" + env: + PR_URL: ${{ github.event.pull_request.html_url }} + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/CHANGELOG.md b/CHANGELOG.md index c523132..6ef4603 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog +## Unreleased + +### Other + +- Auto-merge green Dependabot updates and group the pm toolchain into one daily PR ([pm-context-h34i](https://github.com/unbraind/pm-context/blob/main/.agents/pm/tasks/pm-context-h34i.toon)) + ## 2026.9.26 - 2026-09-26 ### Other