Auto-merge green Dependabot updates and group the pm toolchain into one daily PR - #148
Conversation
…ne daily PR Version bumps of @unbrained/pm-cli, pm-ops and pm-changelog are mechanical. Dependabot now checks npm daily and groups the pm toolchain (and other minor/patch updates) into single pull requests; a least-privilege workflow enables squash auto-merge for every non-major Dependabot PR, so it lands as soon as the required checks pass and a failing bump stays open as a defect. pm item: pm-csv-dida
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 40 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (5)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (5)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Summary by CodeRabbit
WalkthroughDependabot now checks npm dependencies daily and groups pm toolchain updates separately from minor and patch updates. A pull request workflow enables squash auto-merge for eligible Dependabot updates. The changelog and task records document the automation and rollout. ChangesDependabot update automation
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~12 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant Dependabot
participant AutoMergeWorkflow
participant GitHubPullRequest
Dependabot->>GitHubPullRequest: Open dependency update pull request
GitHubPullRequest->>AutoMergeWorkflow: Trigger pull request workflow
AutoMergeWorkflow->>AutoMergeWorkflow: Fetch dependency metadata and check eligibility
AutoMergeWorkflow->>GitHubPullRequest: Enable squash auto-merge
GitHubPullRequest->>GitHubPullRequest: Merge after required checks pass
Merge Risk: ⚪ Minimal · up to Eligible Dependabot updates can enter squash auto-merge, while unrelated major updates remain outside that path. No actionable issue remains before normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The automation is restricted to Dependabot, uses pinned metadata classification, and does not execute dependency code with the merge token. Remaining uncertainty concerns enforcement of required checks and handling of pending auto-merges during rollback. No merge-control bypass was established. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideThe PR changes npm Dependabot polling to daily grouped updates and adds a narrowly scoped, least-privilege workflow that enables squash auto-merge after required checks for the PM toolchain and other non-major Dependabot updates, while retaining manual review for unrelated major updates. Sequence diagram for Dependabot auto-merge workflowsequenceDiagram
participant Dependabot
participant GitHub
participant Workflow as dependabot-auto-merge
participant Metadata as dependabot/fetch-metadata
participant Checks as BranchProtection
Dependabot->>GitHub: Open or update pull request
GitHub->>Workflow: Trigger pull_request
Workflow->>Workflow: Check Dependabot identity and repository owner
Workflow->>Metadata: fetch-metadata
Metadata-->>Workflow: dependency-group and update-type
alt pm-toolchain group or non-major update
Workflow->>GitHub: gh pr merge --auto --squash
GitHub->>Checks: Wait for required checks
alt Checks pass
Checks-->>GitHub: Allow merge
GitHub-->>Dependabot: Squash merge pull request
else Checks fail
Checks-->>GitHub: Keep pull request open
end
else Unrelated major update
Workflow-->>Dependabot: Leave pull request for manual review
end
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
pm item: pm-csv-dida
|
@coderabbitai full review |
✅ Action performedFull review finished. |
…sions Review feedback: an update that fetch-metadata cannot classify must not auto-merge, so the condition now requires semver-minor or semver-patch outside the calendar-versioned pm-toolchain group. The job's write scopes are documented, the dependencies group selects every package explicitly, and the item's acceptance criteria name the pm-toolchain exception. pm item: pm-csv-dida
|
@coderabbitai full review |
|
What
.github/dependabot.yml: npm is checked daily;@unbrained/pm-cliandpm-*packages arrive as onepm-toolchainPR, other minor/patch updates as onedependenciesPR. Other ecosystems are unchanged..github/workflows/dependabot-auto-merge.yml: for Dependabot PRs only (and only inunbraind),dependabot/fetch-metadata(SHA-pinned v3.1.0) classifies the update; thepm-toolchaingroup (calendar-versioned, so a year rollover reads as semver-major) and every other non-major update getgh pr merge --auto --squash. Workflow default permissions are{}; the job alone getscontents: write+pull-requests: write.Why
Fleet rule ([companion pm-cli-website-6d05]): a pm CLI release must reach every package without a hand-written certification PR. Branch protection still requires
test (22),test (26), so nothing merges red; a bump that fails CI stays open as a real defect. Major updates still need a person. Same change as the reviewed pilot unbraind/pm-presets#118.pm item
Summary by Sourcery
Automate the delivery of validated dependency updates while retaining manual review for major non-toolchain releases.
New Features:
Enhancements:
CI:
Documentation:
Chores:
Summary by cubic
Auto-merges green Dependabot updates so pm CLI releases reach every package without a hand-written certification PR.
@unbrained/pm-cliandpm-*packages arrive as onepm-toolchainPR, other minor/patch updates as onedependenciesPR.pm-toolchainalways auto-merges: calendar versions make a year rollover read as semver-major, so it can't rely on the update-type filter. Every other update must be classified bydependabot/fetch-metadataas minor or patch; an unclassified or major update waits for a person.contents: write+pull-requests: write, with the scopes documented) enables squash auto-merge for Dependabot PRs inunbraind.test (22)andtest (26), so a failing bump stays open as a defect instead of merging red.pm-csv-didaand adds a changelog entry.Written for commit ec4f43c. Summary will update on new commits.