Skip to content

Auto-merge green Dependabot updates and group the pm toolchain into one daily PR - #148

Merged
unbraind merged 3 commits into
mainfrom
ci/auto-merge-green-dependabot-updates
Oct 4, 2026
Merged

unbraind merged 3 commits into
mainfrom
ci/auto-merge-green-dependabot-updates

Conversation

@unbraind

@unbraind unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

What

  • .github/dependabot.yml: npm is checked daily; @unbrained/pm-cli and pm-* packages arrive as one pm-toolchain PR, other minor/patch updates as one dependencies PR. Other ecosystems are unchanged.
  • .github/workflows/dependabot-auto-merge.yml: for Dependabot PRs only (and only in unbraind), dependabot/fetch-metadata (SHA-pinned v3.1.0) classifies the update; the pm-toolchain group (calendar-versioned, so a year rollover reads as semver-major) and every other non-major update get gh pr merge --auto --squash. Workflow default permissions are {}; the job alone gets contents: write + pull-requests: write.
  • Repository setting: auto-merge allowed, merged branches deleted.

Why

Fleet rule ([companion pm-cli-website-6d05]): a pm CLI release must reach every package without a hand-written certification PR. Branch protection still requires test (22), test (26), so nothing merges red; a bump that fails CI stays open as a real defect. Major updates still need a person. Same change as the reviewed pilot unbraind/pm-presets#118.

pm item

Summary by Sourcery

Automate the delivery of validated dependency updates while retaining manual review for major non-toolchain releases.

New Features:

  • Enable daily grouping of npm updates, including a dedicated pm toolchain group and a separate minor/patch dependency group.
  • Automatically enable squash auto-merge for green non-major Dependabot updates, including calendar-versioned pm toolchain releases.

Enhancements:

  • Apply least-privilege permissions to the Dependabot auto-merge workflow while preserving branch protection checks.

CI:

  • Add a Dependabot auto-merge workflow that restricts automated merging to Dependabot pull requests in the unbraind organization.

Documentation:

  • Document the Dependabot grouping and auto-merge behavior in the changelog.

Chores:

  • Track the change with the pm-csv-dida work item.

Summary by cubic

Auto-merges green Dependabot updates so pm CLI releases reach every package without a hand-written certification PR.

  • npm updates are now checked daily and grouped: @unbrained/pm-cli and pm-* packages arrive as one pm-toolchain PR, other minor/patch updates as one dependencies PR.
  • pm-toolchain always auto-merges: calendar versions make a year rollover read as semver-major, so it can't rely on the update-type filter. Every other update must be classified by dependabot/fetch-metadata as minor or patch; an unclassified or major update waits for a person.
  • A new least-privilege workflow (default permissions empty, job gets contents: write + pull-requests: write, with the scopes documented) enables squash auto-merge for Dependabot PRs in unbraind.
  • Branch protection still requires test (22) and test (26), so a failing bump stays open as a defect instead of merging red.
  • Tracks the change as pm item pm-csv-dida and adds a changelog entry.

Written for commit ec4f43c. Summary will update on new commits.

Review in cubic

…ne daily PR

Version bumps of @unbrained/pm-cli, pm-ops and pm-changelog are mechanical.
Dependabot now checks npm daily and groups the pm toolchain (and other
minor/patch updates) into single pull requests; a least-privilege workflow
enables squash auto-merge for every non-major Dependabot PR, so it lands as
soon as the required checks pass and a failing bump stays open as a defect.

pm item: pm-csv-dida

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 15 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 40 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: f31bd85c-f3b7-45e8-9f94-c77925368e29
📥 Commits

Reviewing files that changed from the base of the PR and between 2c1cdc6 and ec4f43c.

📒 Files selected for processing (5)
  • .agents/pm/history/pm-csv-dida.jsonl
  • .agents/pm/tasks/pm-csv-dida.toon
  • .github/dependabot.yml
  • .github/workflows/dependabot-auto-merge.yml
  • CHANGELOG.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: f6a18c15-1fd0-4d93-9df6-5558afcca680
📥 Commits

Reviewing files that changed from the base of the PR and between 2c1cdc6 and 2dfb11c.

📒 Files selected for processing (5)
  • .agents/pm/history/pm-csv-dida.jsonl
  • .agents/pm/tasks/pm-csv-dida.toon
  • .github/dependabot.yml
  • .github/workflows/dependabot-auto-merge.yml
  • CHANGELOG.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • Automation

    • Dependency updates are now checked daily and grouped into a single toolchain update or separate minor and patch update groups.
    • Eligible Dependabot updates are automatically merged after required checks pass. Major updates are not included in automatic merges.
  • Documentation

    • Added a changelog entry noting the dependency update automation.

Walkthrough

Dependabot now checks npm dependencies daily and groups pm toolchain updates separately from minor and patch updates. A pull request workflow enables squash auto-merge for eligible Dependabot updates. The changelog and task records document the automation and rollout.

Changes

Dependabot update automation

Layer / File(s) Summary
Schedule and update groups
.github/dependabot.yml
The npm update interval changes from weekly to daily. The configuration groups @unbrained/pm-cli and pm-* packages as pm-toolchain, and limits the separate dependencies group to minor and patch updates.
Auto-merge workflow and rollout records
.github/workflows/dependabot-auto-merge.yml, CHANGELOG.md, .agents/pm/tasks/pm-csv-dida.toon, .agents/pm/history/pm-csv-dida.jsonl
The workflow enables squash auto-merge for pm-toolchain updates or updates that are not semver-major. The changelog and task records describe the automation and record its rollout.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant Dependabot
  participant AutoMergeWorkflow
  participant GitHubPullRequest
  Dependabot->>GitHubPullRequest: Open dependency update pull request
  GitHubPullRequest->>AutoMergeWorkflow: Trigger pull request workflow
  AutoMergeWorkflow->>AutoMergeWorkflow: Fetch dependency metadata and check eligibility
  AutoMergeWorkflow->>GitHubPullRequest: Enable squash auto-merge
  GitHubPullRequest->>GitHubPullRequest: Merge after required checks pass
Loading

Merge Risk: ⚪ Minimal · up to 2dfb1

Eligible Dependabot updates can enter squash auto-merge, while unrelated major updates remain outside that path. No actionable issue remains before normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 2dfb1

The automation is restricted to Dependabot, uses pinned metadata classification, and does not execute dependency code with the merge token. Remaining uncertainty concerns enforcement of required checks and handling of pending auto-merges during rollback. No merge-control bypass was established.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The directly requested write authority concerns this repository’s contents and pull requests, not organization-wide administration. Automatically admitted packages or actions can later execute in the existing main-only release job, extending dependency-admission consequences to repository writes and release identity. Broader downstream authority is not established.

Security Findings and Attack Paths

  • inferred — A compromised eligible upstream package or action release could be proposed by Dependabot and admitted without a new human approval step if configured merge requirements pass. This is a supply-chain trust consequence of the policy, not evidence of a compromised dependency or verified vulnerability. Release permissions predate this PR; the newly introduced change is automatic admission.

Trust Boundaries and Controls

  • observed — Dependabot identity and metadata determine eligibility; GitHub merge policy determines final admission. PR and task text assert required-check enforcement, but no effective branch-protection snapshot is supplied. The workflow itself neither encodes the named required checks nor restricts the target branch.

Hardening Proposals

  • proposed — Verify effective required checks and bypass rules for every reachable target branch before relying on green-only automation, and monitor those settings for drift.
  • proposed — Document rollback ownership and verify platform behavior for changed heads and already-enabled auto-merges. Include cancellation of pending requests when automation is withdrawn if disabling the workflow alone does not revoke them.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main changes: auto-merging eligible Dependabot updates and grouping the pm toolchain into a daily PR.
Description check ✅ Passed The description explains the Dependabot schedule, grouping, auto-merge conditions, permissions, and required checks. It is directly related to the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Reviewer's Guide

The PR changes npm Dependabot polling to daily grouped updates and adds a narrowly scoped, least-privilege workflow that enables squash auto-merge after required checks for the PM toolchain and other non-major Dependabot updates, while retaining manual review for unrelated major updates.

Sequence diagram for Dependabot auto-merge workflow

sequenceDiagram
    participant Dependabot
    participant GitHub
    participant Workflow as dependabot-auto-merge
    participant Metadata as dependabot/fetch-metadata
    participant Checks as BranchProtection

    Dependabot->>GitHub: Open or update pull request
    GitHub->>Workflow: Trigger pull_request
    Workflow->>Workflow: Check Dependabot identity and repository owner
    Workflow->>Metadata: fetch-metadata
    Metadata-->>Workflow: dependency-group and update-type
    alt pm-toolchain group or non-major update
        Workflow->>GitHub: gh pr merge --auto --squash
        GitHub->>Checks: Wait for required checks
        alt Checks pass
            Checks-->>GitHub: Allow merge
            GitHub-->>Dependabot: Squash merge pull request
        else Checks fail
            Checks-->>GitHub: Keep pull request open
        end
    else Unrelated major update
        Workflow-->>Dependabot: Leave pull request for manual review
    end
Loading

File-Level Changes

Change Details Files
Configure daily npm Dependabot updates with explicit package grouping and update-type filtering.
  • Group the PM CLI and pm-prefixed packages into a single daily PR.
  • Group non-PM minor and patch updates separately while excluding PM packages.
  • Leave other ecosystem configuration unchanged.
.github/dependabot.yml
Automatically enable squash auto-merge for eligible Dependabot pull requests while preserving branch-protection checks.
  • Restrict execution to Dependabot PRs in the unbraind organization.
  • Use SHA-pinned Dependabot metadata to identify dependency groups and semantic update types.
  • Auto-merge the pm-toolchain group and all non-major updates; leave unrelated major updates for manual review.
  • Apply empty workflow defaults and grant write permissions only to the job.
.github/workflows/dependabot-auto-merge.yml
Add PM task tracking artifacts for the Dependabot automation work.
  • Record the task and its history entry in the PM metadata files.
.agents/pm/history/pm-csv-dida.jsonl
.agents/pm/tasks/pm-csv-dida.toon

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@greptile-apps

greptile-apps Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Enables automatic merging of dependency updates via GitHub workflow.

The changes since the last review appear safe to merge.

What we checked:

  • Toolchain groups stay separate: The patterns for pm-toolchain are also excluded from dependencies.
  • Unknown updates wait for review: The condition accepts only pm-toolchain, explicit minor updates, or explicit patch updates.

Summary

This PR groups npm updates daily and enables squash auto-merge for eligible Dependabot PRs.

  • The latest changes explicitly include other npm packages in dependencies, while keeping toolchain packages separate.
  • Outside pm-toolchain, only updates classified as minor or patch can enable auto-merge.
  • Task records now describe the calendar-version exception and permission choices.
  • No new actionable issues were found. No previous review threads were supplied.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart TD
  A[Pull request event] --> B{Dependabot PR in unbraind?}
  B -->|No| C[Skip job]
  B -->|Yes| D[Read dependency metadata]
  D --> E{pm-toolchain or classified minor or patch?}
  E -->|No| F[Leave for manual review]
  E -->|Yes| G[Enable squash auto-merge]
  G --> H[GitHub applies repository merge requirements]
Loading

Reviews (3) · Last reviewed commit: "Allow-list minor and patch updates and d..."

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai full review
@greptileai review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

…sions

Review feedback: an update that fetch-metadata cannot classify must not
auto-merge, so the condition now requires semver-minor or semver-patch
outside the calendar-versioned pm-toolchain group. The job's write scopes
are documented, the dependencies group selects every package explicitly,
and the item's acceptance criteria name the pm-toolchain exception.

pm item: pm-csv-dida
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai full review
@greptileai review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 40 minutes.

@unbraind
unbraind merged commit a027803 into main Oct 4, 2026
13 checks passed
@unbraind
unbraind deleted the ci/auto-merge-green-dependabot-updates branch October 4, 2026 18:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant