From 8b62556b3c6bc3c67f43c074a88770a03dbe25e4 Mon Sep 17 00:00:00 2001 From: SteveBot <1153461+unbraind@users.noreply.github.com> Date: Sun, 4 Oct 2026 18:54:21 +0200 Subject: [PATCH 1/3] Auto-merge green Dependabot updates and group the pm toolchain into one daily PR Version bumps of @unbrained/pm-cli, pm-ops and pm-changelog are mechanical. Dependabot now checks npm daily and groups the pm toolchain (and other minor/patch updates) into single pull requests; a least-privilege workflow enables squash auto-merge for every non-major Dependabot PR, so it lands as soon as the required checks pass and a failing bump stays open as a defect. pm item: pm-context-h34i --- .agents/pm/history/pm-context-h34i.jsonl | 3 +++ .agents/pm/tasks/pm-context-h34i.toon | 23 ++++++++++++++++++ .github/dependabot.yml | 21 ++++++++++++++++- .github/workflows/dependabot-auto-merge.yml | 26 +++++++++++++++++++++ 4 files changed, 72 insertions(+), 1 deletion(-) create mode 100644 .agents/pm/history/pm-context-h34i.jsonl create mode 100644 .agents/pm/tasks/pm-context-h34i.toon create mode 100644 .github/workflows/dependabot-auto-merge.yml diff --git a/.agents/pm/history/pm-context-h34i.jsonl b/.agents/pm/history/pm-context-h34i.jsonl new file mode 100644 index 0000000..bf7cbb8 --- /dev/null +++ b/.agents/pm/history/pm-context-h34i.jsonl @@ -0,0 +1,3 @@ +{"hash_algorithm":"sha256","ts":"2026-10-04T16:54:19.945Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"create","patch":[{"op":"replace","path":"/body","value":"Fleet-wide automation of version bumps; see companion pm-cli-website-6d05."},{"op":"add","path":"/metadata/id","value":"pm-context-h34i"},{"op":"add","path":"/metadata/title","value":"Auto-merge green Dependabot updates and group the pm toolchain into one daily PR"},{"op":"add","path":"/metadata/description","value":"Version bumps of the pm CLI, SDK-bearing packages and fleet gates are mechanical and must land without a hand-written certification PR. Dependabot checks npm daily, groups @unbrained/pm-cli and pm-* packages into one pm-toolchain PR and other minor/patch updates into one dependencies PR; a least-privilege workflow enables GitHub squash auto-merge for every non-major Dependabot PR so it merges as soon as the required checks pass. A failing bump is a real defect to fix. Fleet rule: companion pm-cli-website-6d05; pilot unbraind/pm-presets#118."},{"op":"add","path":"/metadata/type","value":"Task"},{"op":"add","path":"/metadata/status","value":"open"},{"op":"add","path":"/metadata/priority","value":2},{"op":"add","path":"/metadata/tags","value":["automation","ci","dependencies"]},{"op":"add","path":"/metadata/created_at","value":"2026-10-04T16:54:19.945Z"},{"op":"add","path":"/metadata/updated_at","value":"2026-10-04T16:54:19.945Z"},{"op":"add","path":"/metadata/deadline","value":"2026-10-06T00:00:00.000Z"},{"op":"add","path":"/metadata/assignee","value":"claude-orchestrator"},{"op":"add","path":"/metadata/author","value":"claude-orchestrator"},{"op":"add","path":"/metadata/estimated_minutes","value":15},{"op":"add","path":"/metadata/acceptance_criteria","value":"dependabot.yml checks npm daily with pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge only for Dependabot non-major updates with least-privilege permissions; repository allows auto-merge; required checks still gate every merge"},{"op":"add","path":"/metadata/comments","value":[{"created_at":"2026-10-04T16:54:19.945Z","author":"claude-orchestrator","text":"Rolled out from the reviewed pilot unbraind/pm-presets#118."}]},{"op":"add","path":"/metadata/files","value":[{"path":".github/dependabot.yml","scope":"project"},{"path":".github/workflows/dependabot-auto-merge.yml","scope":"project"}]},{"op":"add","path":"/metadata/docs","value":[{"path":".github/workflows/dependabot-auto-merge.yml","scope":"project"}]}],"before_hash":"3cc22dff72be7b14824654a7a64ea62b04799939b2fee54c1b5f52ca60bf6df0","after_hash":"18f430392952983034e7b2c36b30a6b767f653909d756dde74728cc7fa035a47","item_hash_version":3,"message":"Create item for Dependabot auto-merge | explicit_unset=dependencies,learnings,notes,tests","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"cbbd54e6a87973157849d6a401062b049d1592f6e20c9dc37e3de82754032bd9"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:54:20.646Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"claim","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:54:20.646Z"},{"op":"add","path":"/metadata/claim_principal","value":"claude-orchestrator"}],"before_hash":"18f430392952983034e7b2c36b30a6b767f653909d756dde74728cc7fa035a47","after_hash":"4941058d7817f5bb5269dc535f7b4ddd461d88b276bd903e8e6c1f0ea98f2195","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"962e69704083464ee6105d1936d8bb8e727b28dc9636d0f758c72673b07a4b07"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:54:21.331Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:54:21.331Z"},{"op":"replace","path":"/metadata/status","value":"in_progress"}],"before_hash":"4941058d7817f5bb5269dc535f7b4ddd461d88b276bd903e8e6c1f0ea98f2195","after_hash":"a68e52721516f8080b0d3249aedf5d163d682bdb1ae05095c9a3e5e8a8a1c3ca","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"41c3eda19881f702219bd0daf409186a290b515b31c927181b9690abd9b56faf"} diff --git a/.agents/pm/tasks/pm-context-h34i.toon b/.agents/pm/tasks/pm-context-h34i.toon new file mode 100644 index 0000000..693a0c7 --- /dev/null +++ b/.agents/pm/tasks/pm-context-h34i.toon @@ -0,0 +1,23 @@ +id: pm-context-h34i +title: Auto-merge green Dependabot updates and group the pm toolchain into one daily PR +description: "Version bumps of the pm CLI, SDK-bearing packages and fleet gates are mechanical and must land without a hand-written certification PR. Dependabot checks npm daily, groups @unbrained/pm-cli and pm-* packages into one pm-toolchain PR and other minor/patch updates into one dependencies PR; a least-privilege workflow enables GitHub squash auto-merge for every non-major Dependabot PR so it merges as soon as the required checks pass. A failing bump is a real defect to fix. Fleet rule: companion pm-cli-website-6d05; pilot unbraind/pm-presets#118." +type: Task +status: in_progress +priority: 2 +tags[3]: automation,ci,dependencies +created_at: "2026-10-04T16:54:19.945Z" +updated_at: "2026-10-04T16:54:21.331Z" +deadline: "2026-10-06T00:00:00.000Z" +assignee: claude-orchestrator +claim_principal: claude-orchestrator +author: claude-orchestrator +estimated_minutes: 15 +acceptance_criteria: dependabot.yml checks npm daily with pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge only for Dependabot non-major updates with least-privilege permissions; repository allows auto-merge; required checks still gate every merge +comments[1]{created_at,author,text}: + "2026-10-04T16:54:19.945Z",claude-orchestrator,Rolled out from the reviewed pilot unbraind/pm-presets#118. +files[2]{path,scope}: + .github/dependabot.yml,project + .github/workflows/dependabot-auto-merge.yml,project +docs[1]{path,scope}: + .github/workflows/dependabot-auto-merge.yml,project +body: Fleet-wide automation of version bumps; see companion pm-cli-website-6d05. diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 35d995d..7d59863 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -3,8 +3,27 @@ updates: - package-ecosystem: "npm" directory: "/" schedule: - interval: "weekly" + interval: "daily" open-pull-requests-limit: 5 + groups: + # The pm CLI, its SDK-bearing packages and the fleet gates move together + # in one pull request per day; dependabot-auto-merge.yml merges it as soon + # as the required checks pass, so a release bump needs no manual work. + # No update-types filter: pm uses calendar versions, so a year rollover + # (2026.x -> 2027.x) is a semver major that must still land unattended. + pm-toolchain: + patterns: + - "@unbrained/pm-cli" + - "pm-*" + dependencies: + # Disjoint from pm-toolchain, so a pm package can never be bumped + # here (and capped by this group's update-types) instead. + exclude-patterns: + - "@unbrained/pm-cli" + - "pm-*" + update-types: + - "minor" + - "patch" - package-ecosystem: "github-actions" directory: "/" diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml new file mode 100644 index 0000000..12eab3b --- /dev/null +++ b/.github/workflows/dependabot-auto-merge.yml @@ -0,0 +1,26 @@ +name: dependabot-auto-merge + +# Version bumps are mechanical: every non-major Dependabot pull request gets +# GitHub auto-merge, so it lands the moment the required checks pass. Branch +# protection still gates the merge; a failing bump stays open as a defect. +on: pull_request + +permissions: {} + +jobs: + enable-auto-merge: + if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository_owner == 'unbraind' + runs-on: ubuntu-latest + permissions: + contents: write + pull-requests: write + steps: + - id: metadata + uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 + # pm-toolchain is calendar-versioned (a new year reads as semver-major), + # so it always auto-merges; any other major update waits for a person. + - if: steps.metadata.outputs.dependency-group == 'pm-toolchain' || steps.metadata.outputs.update-type != 'version-update:semver-major' + run: gh pr merge --auto --squash "$PR_URL" + env: + PR_URL: ${{ github.event.pull_request.html_url }} + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} From c3e1d5f17aade07f06cc51646073a4e0b47d37bd Mon Sep 17 00:00:00 2001 From: SteveBot <1153461+unbraind@users.noreply.github.com> Date: Sun, 4 Oct 2026 19:01:36 +0200 Subject: [PATCH 2/3] Close pm-context-h34i and regenerate the changelog pm item: pm-context-h34i --- .agents/pm/history/pm-context-h34i.jsonl | 2 ++ .agents/pm/tasks/pm-context-h34i.toon | 9 +++++---- CHANGELOG.md | 6 ++++++ 3 files changed, 13 insertions(+), 4 deletions(-) diff --git a/.agents/pm/history/pm-context-h34i.jsonl b/.agents/pm/history/pm-context-h34i.jsonl index bf7cbb8..4d23002 100644 --- a/.agents/pm/history/pm-context-h34i.jsonl +++ b/.agents/pm/history/pm-context-h34i.jsonl @@ -1,3 +1,5 @@ {"hash_algorithm":"sha256","ts":"2026-10-04T16:54:19.945Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"create","patch":[{"op":"replace","path":"/body","value":"Fleet-wide automation of version bumps; see companion pm-cli-website-6d05."},{"op":"add","path":"/metadata/id","value":"pm-context-h34i"},{"op":"add","path":"/metadata/title","value":"Auto-merge green Dependabot updates and group the pm toolchain into one daily PR"},{"op":"add","path":"/metadata/description","value":"Version bumps of the pm CLI, SDK-bearing packages and fleet gates are mechanical and must land without a hand-written certification PR. Dependabot checks npm daily, groups @unbrained/pm-cli and pm-* packages into one pm-toolchain PR and other minor/patch updates into one dependencies PR; a least-privilege workflow enables GitHub squash auto-merge for every non-major Dependabot PR so it merges as soon as the required checks pass. A failing bump is a real defect to fix. Fleet rule: companion pm-cli-website-6d05; pilot unbraind/pm-presets#118."},{"op":"add","path":"/metadata/type","value":"Task"},{"op":"add","path":"/metadata/status","value":"open"},{"op":"add","path":"/metadata/priority","value":2},{"op":"add","path":"/metadata/tags","value":["automation","ci","dependencies"]},{"op":"add","path":"/metadata/created_at","value":"2026-10-04T16:54:19.945Z"},{"op":"add","path":"/metadata/updated_at","value":"2026-10-04T16:54:19.945Z"},{"op":"add","path":"/metadata/deadline","value":"2026-10-06T00:00:00.000Z"},{"op":"add","path":"/metadata/assignee","value":"claude-orchestrator"},{"op":"add","path":"/metadata/author","value":"claude-orchestrator"},{"op":"add","path":"/metadata/estimated_minutes","value":15},{"op":"add","path":"/metadata/acceptance_criteria","value":"dependabot.yml checks npm daily with pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge only for Dependabot non-major updates with least-privilege permissions; repository allows auto-merge; required checks still gate every merge"},{"op":"add","path":"/metadata/comments","value":[{"created_at":"2026-10-04T16:54:19.945Z","author":"claude-orchestrator","text":"Rolled out from the reviewed pilot unbraind/pm-presets#118."}]},{"op":"add","path":"/metadata/files","value":[{"path":".github/dependabot.yml","scope":"project"},{"path":".github/workflows/dependabot-auto-merge.yml","scope":"project"}]},{"op":"add","path":"/metadata/docs","value":[{"path":".github/workflows/dependabot-auto-merge.yml","scope":"project"}]}],"before_hash":"3cc22dff72be7b14824654a7a64ea62b04799939b2fee54c1b5f52ca60bf6df0","after_hash":"18f430392952983034e7b2c36b30a6b767f653909d756dde74728cc7fa035a47","item_hash_version":3,"message":"Create item for Dependabot auto-merge | explicit_unset=dependencies,learnings,notes,tests","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"cbbd54e6a87973157849d6a401062b049d1592f6e20c9dc37e3de82754032bd9"} {"hash_algorithm":"sha256","ts":"2026-10-04T16:54:20.646Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"claim","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:54:20.646Z"},{"op":"add","path":"/metadata/claim_principal","value":"claude-orchestrator"}],"before_hash":"18f430392952983034e7b2c36b30a6b767f653909d756dde74728cc7fa035a47","after_hash":"4941058d7817f5bb5269dc535f7b4ddd461d88b276bd903e8e6c1f0ea98f2195","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"962e69704083464ee6105d1936d8bb8e727b28dc9636d0f758c72673b07a4b07"} {"hash_algorithm":"sha256","ts":"2026-10-04T16:54:21.331Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:54:21.331Z"},{"op":"replace","path":"/metadata/status","value":"in_progress"}],"before_hash":"4941058d7817f5bb5269dc535f7b4ddd461d88b276bd903e8e6c1f0ea98f2195","after_hash":"a68e52721516f8080b0d3249aedf5d163d682bdb1ae05095c9a3e5e8a8a1c3ca","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"41c3eda19881f702219bd0daf409186a290b515b31c927181b9690abd9b56faf"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:58:39.003Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"close","patch":[{"op":"remove","path":"/metadata/assignee"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:58:39.003Z"},{"op":"replace","path":"/metadata/status","value":"closed"},{"op":"add","path":"/metadata/closed_at","value":"2026-10-04T16:58:38.695Z"},{"op":"add","path":"/metadata/completed_at","value":"2026-10-04T16:58:38.695Z"},{"op":"add","path":"/metadata/close_reason","value":"Rolled out the reviewed pilot (unbraind/pm-presets#118, auto-merge proven on pm-presets#119, groups made disjoint in pm-presets#120). This PR's required checks gate the merge; repository auto-merge and branch deletion enabled."}],"before_hash":"a68e52721516f8080b0d3249aedf5d163d682bdb1ae05095c9a3e5e8a8a1c3ca","after_hash":"f4ffbdff1005d360ac231fb85dad4002133a18e817d41fdfaf38266fab679149","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"eda26648703590bc2aef947075148bddd372c00cb3c6063377ba435eaec64531"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:58:46.312Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"release","patch":[{"op":"remove","path":"/metadata/claim_principal"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:58:46.312Z"}],"before_hash":"f4ffbdff1005d360ac231fb85dad4002133a18e817d41fdfaf38266fab679149","after_hash":"ffa3937356b905ea8271cdc5a850c0d3160f976765684dc51306ca6d619c3d81","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"6127b3b40a92c479227ef4bd1c4e266603c227fc807ab0500f4d2b5143e35da7"} diff --git a/.agents/pm/tasks/pm-context-h34i.toon b/.agents/pm/tasks/pm-context-h34i.toon index 693a0c7..7a7313d 100644 --- a/.agents/pm/tasks/pm-context-h34i.toon +++ b/.agents/pm/tasks/pm-context-h34i.toon @@ -2,14 +2,14 @@ id: pm-context-h34i title: Auto-merge green Dependabot updates and group the pm toolchain into one daily PR description: "Version bumps of the pm CLI, SDK-bearing packages and fleet gates are mechanical and must land without a hand-written certification PR. Dependabot checks npm daily, groups @unbrained/pm-cli and pm-* packages into one pm-toolchain PR and other minor/patch updates into one dependencies PR; a least-privilege workflow enables GitHub squash auto-merge for every non-major Dependabot PR so it merges as soon as the required checks pass. A failing bump is a real defect to fix. Fleet rule: companion pm-cli-website-6d05; pilot unbraind/pm-presets#118." type: Task -status: in_progress +status: closed priority: 2 tags[3]: automation,ci,dependencies created_at: "2026-10-04T16:54:19.945Z" -updated_at: "2026-10-04T16:54:21.331Z" +updated_at: "2026-10-04T16:58:46.312Z" deadline: "2026-10-06T00:00:00.000Z" -assignee: claude-orchestrator -claim_principal: claude-orchestrator +closed_at: "2026-10-04T16:58:38.695Z" +completed_at: "2026-10-04T16:58:38.695Z" author: claude-orchestrator estimated_minutes: 15 acceptance_criteria: dependabot.yml checks npm daily with pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge only for Dependabot non-major updates with least-privilege permissions; repository allows auto-merge; required checks still gate every merge @@ -20,4 +20,5 @@ files[2]{path,scope}: .github/workflows/dependabot-auto-merge.yml,project docs[1]{path,scope}: .github/workflows/dependabot-auto-merge.yml,project +close_reason: "Rolled out the reviewed pilot (unbraind/pm-presets#118, auto-merge proven on pm-presets#119, groups made disjoint in pm-presets#120). This PR's required checks gate the merge; repository auto-merge and branch deletion enabled." body: Fleet-wide automation of version bumps; see companion pm-cli-website-6d05. diff --git a/CHANGELOG.md b/CHANGELOG.md index c523132..6ef4603 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog +## Unreleased + +### Other + +- Auto-merge green Dependabot updates and group the pm toolchain into one daily PR ([pm-context-h34i](https://github.com/unbraind/pm-context/blob/main/.agents/pm/tasks/pm-context-h34i.toon)) + ## 2026.9.26 - 2026-09-26 ### Other From 47e972b05f9eaea3f04d60adf0bb730c6b585809 Mon Sep 17 00:00:00 2001 From: SteveBot <1153461+unbraind@users.noreply.github.com> Date: Sun, 4 Oct 2026 19:21:05 +0200 Subject: [PATCH 3/3] Allow-list minor and patch updates and document the auto-merge permissions Review feedback: an update that fetch-metadata cannot classify must not auto-merge, so the condition now requires semver-minor or semver-patch outside the calendar-versioned pm-toolchain group. The job's write scopes are documented, the dependencies group selects every package explicitly, and the item's acceptance criteria name the pm-toolchain exception. pm item: pm-context-h34i --- .agents/pm/history/pm-context-h34i.jsonl | 2 ++ .agents/pm/tasks/pm-context-h34i.toon | 7 ++++--- .github/dependabot.yml | 6 ++++-- .github/workflows/dependabot-auto-merge.yml | 11 +++++++++-- 4 files changed, 19 insertions(+), 7 deletions(-) diff --git a/.agents/pm/history/pm-context-h34i.jsonl b/.agents/pm/history/pm-context-h34i.jsonl index 4d23002..1b50947 100644 --- a/.agents/pm/history/pm-context-h34i.jsonl +++ b/.agents/pm/history/pm-context-h34i.jsonl @@ -3,3 +3,5 @@ {"hash_algorithm":"sha256","ts":"2026-10-04T16:54:21.331Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:54:21.331Z"},{"op":"replace","path":"/metadata/status","value":"in_progress"}],"before_hash":"4941058d7817f5bb5269dc535f7b4ddd461d88b276bd903e8e6c1f0ea98f2195","after_hash":"a68e52721516f8080b0d3249aedf5d163d682bdb1ae05095c9a3e5e8a8a1c3ca","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"41c3eda19881f702219bd0daf409186a290b515b31c927181b9690abd9b56faf"} {"hash_algorithm":"sha256","ts":"2026-10-04T16:58:39.003Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"close","patch":[{"op":"remove","path":"/metadata/assignee"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:58:39.003Z"},{"op":"replace","path":"/metadata/status","value":"closed"},{"op":"add","path":"/metadata/closed_at","value":"2026-10-04T16:58:38.695Z"},{"op":"add","path":"/metadata/completed_at","value":"2026-10-04T16:58:38.695Z"},{"op":"add","path":"/metadata/close_reason","value":"Rolled out the reviewed pilot (unbraind/pm-presets#118, auto-merge proven on pm-presets#119, groups made disjoint in pm-presets#120). This PR's required checks gate the merge; repository auto-merge and branch deletion enabled."}],"before_hash":"a68e52721516f8080b0d3249aedf5d163d682bdb1ae05095c9a3e5e8a8a1c3ca","after_hash":"f4ffbdff1005d360ac231fb85dad4002133a18e817d41fdfaf38266fab679149","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"eda26648703590bc2aef947075148bddd372c00cb3c6063377ba435eaec64531"} {"hash_algorithm":"sha256","ts":"2026-10-04T16:58:46.312Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"release","patch":[{"op":"remove","path":"/metadata/claim_principal"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:58:46.312Z"}],"before_hash":"f4ffbdff1005d360ac231fb85dad4002133a18e817d41fdfaf38266fab679149","after_hash":"ffa3937356b905ea8271cdc5a850c0d3160f976765684dc51306ca6d619c3d81","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"6127b3b40a92c479227ef4bd1c4e266603c227fc807ab0500f4d2b5143e35da7"} +{"hash_algorithm":"sha256","ts":"2026-10-04T17:20:35.030Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"update","patch":[{"op":"replace","path":"/metadata/acceptance_criteria","value":"dependabot.yml checks npm daily with disjoint pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge for the calendar-versioned pm-toolchain group (year rollovers read as semver-major) and otherwise only for updates classified minor or patch, with documented least-privilege permissions; repository allows auto-merge; required checks still gate every merge"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T17:20:35.030Z"}],"before_hash":"ffa3937356b905ea8271cdc5a850c0d3160f976765684dc51306ca6d619c3d81","after_hash":"6b2a6247a2798b0589daf7e2983cf66fb5c5a3b994cbf32cdcc548d9a0d2dfb8","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"4091361b6f718e6a987c926f24fe03c6d8b98f92a574ca0553717c999f38314d"} +{"hash_algorithm":"sha256","ts":"2026-10-04T17:20:41.728Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":null,"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"comment_add","patch":[{"op":"add","path":"/metadata/comments/1","value":{"created_at":"2026-10-04T17:20:41.728Z","author":"claude-orchestrator","text":"Review round 2 (Greptile/CodeRabbit across the fleet rollout): explicit minor/patch allow-list so an unclassified update never auto-merges; documented why the job needs write permissions; explicit patterns for the dependencies group; acceptance criteria now name the pm-toolchain calendar-version exception. Refused: switching to pull_request_target (GitHub keeps Dependabot-authored runs read-only there too; the pull_request + permissions pattern is proven by pm-presets#119) and removing the pm-toolchain exception (owner rule pm-cli-website-6d05: pm bumps land unattended; required checks gate them)."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T17:20:41.728Z"}],"before_hash":"6b2a6247a2798b0589daf7e2983cf66fb5c5a3b994cbf32cdcc548d9a0d2dfb8","after_hash":"63e56121b8e4cdfea6bdc7f685774d88f626005454fa31f8a163913f3935556e","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"c31249d660f59507f3f7a1b280500ba324f506a9dbbfb06a5910e84a3620e340"} diff --git a/.agents/pm/tasks/pm-context-h34i.toon b/.agents/pm/tasks/pm-context-h34i.toon index 7a7313d..d94d4e5 100644 --- a/.agents/pm/tasks/pm-context-h34i.toon +++ b/.agents/pm/tasks/pm-context-h34i.toon @@ -6,15 +6,16 @@ status: closed priority: 2 tags[3]: automation,ci,dependencies created_at: "2026-10-04T16:54:19.945Z" -updated_at: "2026-10-04T16:58:46.312Z" +updated_at: "2026-10-04T17:20:41.728Z" deadline: "2026-10-06T00:00:00.000Z" closed_at: "2026-10-04T16:58:38.695Z" completed_at: "2026-10-04T16:58:38.695Z" author: claude-orchestrator estimated_minutes: 15 -acceptance_criteria: dependabot.yml checks npm daily with pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge only for Dependabot non-major updates with least-privilege permissions; repository allows auto-merge; required checks still gate every merge -comments[1]{created_at,author,text}: +acceptance_criteria: "dependabot.yml checks npm daily with disjoint pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge for the calendar-versioned pm-toolchain group (year rollovers read as semver-major) and otherwise only for updates classified minor or patch, with documented least-privilege permissions; repository allows auto-merge; required checks still gate every merge" +comments[2]{created_at,author,text}: "2026-10-04T16:54:19.945Z",claude-orchestrator,Rolled out from the reviewed pilot unbraind/pm-presets#118. + "2026-10-04T17:20:41.728Z",claude-orchestrator,"Review round 2 (Greptile/CodeRabbit across the fleet rollout): explicit minor/patch allow-list so an unclassified update never auto-merges; documented why the job needs write permissions; explicit patterns for the dependencies group; acceptance criteria now name the pm-toolchain calendar-version exception. Refused: switching to pull_request_target (GitHub keeps Dependabot-authored runs read-only there too; the pull_request + permissions pattern is proven by pm-presets#119) and removing the pm-toolchain exception (owner rule pm-cli-website-6d05: pm bumps land unattended; required checks gate them)." files[2]{path,scope}: .github/dependabot.yml,project .github/workflows/dependabot-auto-merge.yml,project diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 7d59863..82f0b16 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -16,8 +16,10 @@ updates: - "@unbrained/pm-cli" - "pm-*" dependencies: - # Disjoint from pm-toolchain, so a pm package can never be bumped - # here (and capped by this group's update-types) instead. + # Every other npm dependency, disjoint from pm-toolchain, so a pm + # package can never be bumped here (and capped by update-types). + patterns: + - "*" exclude-patterns: - "@unbrained/pm-cli" - "pm-*" diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index 12eab3b..85d4c77 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -11,6 +11,9 @@ jobs: enable-auto-merge: if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository_owner == 'unbraind' runs-on: ubuntu-latest + # `gh pr merge --auto` needs pull-requests: write to enable auto-merge + # and contents: write for the squash merge GitHub performs once the + # required checks pass. Nothing is checked out or executed from the PR. permissions: contents: write pull-requests: write @@ -18,8 +21,12 @@ jobs: - id: metadata uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 # pm-toolchain is calendar-versioned (a new year reads as semver-major), - # so it always auto-merges; any other major update waits for a person. - - if: steps.metadata.outputs.dependency-group == 'pm-toolchain' || steps.metadata.outputs.update-type != 'version-update:semver-major' + # so it always auto-merges. Anything else must be classified minor or + # patch; a major or unclassified update waits for a person. + - if: >- + steps.metadata.outputs.dependency-group == 'pm-toolchain' || + steps.metadata.outputs.update-type == 'version-update:semver-minor' || + steps.metadata.outputs.update-type == 'version-update:semver-patch' run: gh pr merge --auto --squash "$PR_URL" env: PR_URL: ${{ github.event.pull_request.html_url }}