diff --git a/.agents/pm/history/pm-github-u9df.jsonl b/.agents/pm/history/pm-github-u9df.jsonl new file mode 100644 index 0000000..5589e52 --- /dev/null +++ b/.agents/pm/history/pm-github-u9df.jsonl @@ -0,0 +1,7 @@ +{"hash_algorithm":"sha256","ts":"2026-10-04T16:54:44.174Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"create","patch":[{"op":"replace","path":"/body","value":"Fleet-wide automation of version bumps; see companion pm-cli-website-6d05."},{"op":"add","path":"/metadata/id","value":"pm-github-u9df"},{"op":"add","path":"/metadata/title","value":"Auto-merge green Dependabot updates and group the pm toolchain into one daily PR"},{"op":"add","path":"/metadata/description","value":"Version bumps of the pm CLI, SDK-bearing packages and fleet gates are mechanical and must land without a hand-written certification PR. Dependabot checks npm daily, groups @unbrained/pm-cli and pm-* packages into one pm-toolchain PR and other minor/patch updates into one dependencies PR; a least-privilege workflow enables GitHub squash auto-merge for every non-major Dependabot PR so it merges as soon as the required checks pass. A failing bump is a real defect to fix. Fleet rule: companion pm-cli-website-6d05; pilot unbraind/pm-presets#118."},{"op":"add","path":"/metadata/type","value":"Task"},{"op":"add","path":"/metadata/status","value":"open"},{"op":"add","path":"/metadata/priority","value":2},{"op":"add","path":"/metadata/tags","value":["automation","ci","dependencies"]},{"op":"add","path":"/metadata/created_at","value":"2026-10-04T16:54:44.174Z"},{"op":"add","path":"/metadata/updated_at","value":"2026-10-04T16:54:44.174Z"},{"op":"add","path":"/metadata/deadline","value":"2026-10-06T00:00:00.000Z"},{"op":"add","path":"/metadata/assignee","value":"claude-orchestrator"},{"op":"add","path":"/metadata/author","value":"claude-orchestrator"},{"op":"add","path":"/metadata/estimated_minutes","value":15},{"op":"add","path":"/metadata/acceptance_criteria","value":"dependabot.yml checks npm daily with pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge only for Dependabot non-major updates with least-privilege permissions; repository allows auto-merge; required checks still gate every merge"},{"op":"add","path":"/metadata/comments","value":[{"created_at":"2026-10-04T16:54:44.174Z","author":"claude-orchestrator","text":"Rolled out from the reviewed pilot unbraind/pm-presets#118."}]},{"op":"add","path":"/metadata/files","value":[{"path":".github/dependabot.yml","scope":"project"},{"path":".github/workflows/dependabot-auto-merge.yml","scope":"project"}]},{"op":"add","path":"/metadata/docs","value":[{"path":".github/workflows/dependabot-auto-merge.yml","scope":"project"}]}],"before_hash":"3cc22dff72be7b14824654a7a64ea62b04799939b2fee54c1b5f52ca60bf6df0","after_hash":"56745bd2b9327db77cf1526ec0b144671215a0309e265c204b7f3cb23e7db7fc","item_hash_version":3,"message":"Create item for Dependabot auto-merge | explicit_unset=dependencies,learnings,notes,tests","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"dab325a1a90617b733c0f3ae43d1643fc023f170443d837195f7d9fe29e83379"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:54:44.953Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"claim","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:54:44.953Z"},{"op":"add","path":"/metadata/claim_principal","value":"claude-orchestrator"}],"before_hash":"56745bd2b9327db77cf1526ec0b144671215a0309e265c204b7f3cb23e7db7fc","after_hash":"89e961d7bdaab4b7437b034978674b447c815488d11932bd07e0fd7b9f443708","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"d27af742dc8181ee9d3c08bc6241427962ca0a9d45bd2f006c0675c456932531"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:54:45.783Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:54:45.783Z"},{"op":"replace","path":"/metadata/status","value":"in_progress"}],"before_hash":"89e961d7bdaab4b7437b034978674b447c815488d11932bd07e0fd7b9f443708","after_hash":"6a44b0d7ac85d905d1db638199bcd222de7c0612f547a5e42d9078e09b9c299d","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"d72cacb324c4091cb87ea7f8a8467b25d46473b7f787b323b9b0d937274a5b19"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:58:39.102Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"close","patch":[{"op":"remove","path":"/metadata/assignee"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:58:39.102Z"},{"op":"replace","path":"/metadata/status","value":"closed"},{"op":"add","path":"/metadata/closed_at","value":"2026-10-04T16:58:38.805Z"},{"op":"add","path":"/metadata/completed_at","value":"2026-10-04T16:58:38.805Z"},{"op":"add","path":"/metadata/close_reason","value":"Rolled out the reviewed pilot (unbraind/pm-presets#118, auto-merge proven on pm-presets#119, groups made disjoint in pm-presets#120). This PR's required checks gate the merge; repository auto-merge and branch deletion enabled."}],"before_hash":"6a44b0d7ac85d905d1db638199bcd222de7c0612f547a5e42d9078e09b9c299d","after_hash":"b033c0c7daccef4a863755047368f8703e78b525e8babd6e222a2140281c9b53","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"ccf3a24cbbdc5f2f205670e41b4154c0a644b4e472b29aad8dafea6b64f8fe2d"} +{"hash_algorithm":"sha256","ts":"2026-10-04T16:58:45.378Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"release","patch":[{"op":"remove","path":"/metadata/claim_principal"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:58:45.378Z"}],"before_hash":"b033c0c7daccef4a863755047368f8703e78b525e8babd6e222a2140281c9b53","after_hash":"ead6aded286bd1eb764b5663c86cb83e2e8ff1f2ce14320959deec08338a4279","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"5b056fb1ca9c9216bdf6a6c3502bf313ba40cf357b739cea4df194f76f728263"} +{"hash_algorithm":"sha256","ts":"2026-10-04T17:20:34.300Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"update","patch":[{"op":"replace","path":"/metadata/acceptance_criteria","value":"dependabot.yml checks npm daily with disjoint pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge for the calendar-versioned pm-toolchain group (year rollovers read as semver-major) and otherwise only for updates classified minor or patch, with documented least-privilege permissions; repository allows auto-merge; required checks still gate every merge"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T17:20:34.300Z"}],"before_hash":"ead6aded286bd1eb764b5663c86cb83e2e8ff1f2ce14320959deec08338a4279","after_hash":"04dc48a8bf6f8a795477c2a5747499f110014fbc06b2b36ae8919f3b363f1590","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"1913931dbfe3188242a4af2ba274b3394456c0de7667fb8f731dd4387bf93fbc"} +{"hash_algorithm":"sha256","ts":"2026-10-04T17:20:40.427Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":null,"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"comment_add","patch":[{"op":"add","path":"/metadata/comments/1","value":{"created_at":"2026-10-04T17:20:40.427Z","author":"claude-orchestrator","text":"Review round 2 (Greptile/CodeRabbit across the fleet rollout): explicit minor/patch allow-list so an unclassified update never auto-merges; documented why the job needs write permissions; explicit patterns for the dependencies group; acceptance criteria now name the pm-toolchain calendar-version exception. Refused: switching to pull_request_target (GitHub keeps Dependabot-authored runs read-only there too; the pull_request + permissions pattern is proven by pm-presets#119) and removing the pm-toolchain exception (owner rule pm-cli-website-6d05: pm bumps land unattended; required checks gate them)."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T17:20:40.427Z"}],"before_hash":"04dc48a8bf6f8a795477c2a5747499f110014fbc06b2b36ae8919f3b363f1590","after_hash":"8da90c032ff012191c949f713edc123054c744e10990ebd78cb60963a1ae6b80","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"fb085bab6a15b6cb5060de7f2abf0d1edac7ed568cd8f6cf270a81786b222e8f"} diff --git a/.agents/pm/tasks/pm-github-u9df.toon b/.agents/pm/tasks/pm-github-u9df.toon new file mode 100644 index 0000000..79f6f99 --- /dev/null +++ b/.agents/pm/tasks/pm-github-u9df.toon @@ -0,0 +1,25 @@ +id: pm-github-u9df +title: Auto-merge green Dependabot updates and group the pm toolchain into one daily PR +description: "Version bumps of the pm CLI, SDK-bearing packages and fleet gates are mechanical and must land without a hand-written certification PR. Dependabot checks npm daily, groups @unbrained/pm-cli and pm-* packages into one pm-toolchain PR and other minor/patch updates into one dependencies PR; a least-privilege workflow enables GitHub squash auto-merge for every non-major Dependabot PR so it merges as soon as the required checks pass. A failing bump is a real defect to fix. Fleet rule: companion pm-cli-website-6d05; pilot unbraind/pm-presets#118." +type: Task +status: closed +priority: 2 +tags[3]: automation,ci,dependencies +created_at: "2026-10-04T16:54:44.174Z" +updated_at: "2026-10-04T17:20:40.427Z" +deadline: "2026-10-06T00:00:00.000Z" +closed_at: "2026-10-04T16:58:38.805Z" +completed_at: "2026-10-04T16:58:38.805Z" +author: claude-orchestrator +estimated_minutes: 15 +acceptance_criteria: "dependabot.yml checks npm daily with disjoint pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge for the calendar-versioned pm-toolchain group (year rollovers read as semver-major) and otherwise only for updates classified minor or patch, with documented least-privilege permissions; repository allows auto-merge; required checks still gate every merge" +comments[2]{created_at,author,text}: + "2026-10-04T16:54:44.174Z",claude-orchestrator,Rolled out from the reviewed pilot unbraind/pm-presets#118. + "2026-10-04T17:20:40.427Z",claude-orchestrator,"Review round 2 (Greptile/CodeRabbit across the fleet rollout): explicit minor/patch allow-list so an unclassified update never auto-merges; documented why the job needs write permissions; explicit patterns for the dependencies group; acceptance criteria now name the pm-toolchain calendar-version exception. Refused: switching to pull_request_target (GitHub keeps Dependabot-authored runs read-only there too; the pull_request + permissions pattern is proven by pm-presets#119) and removing the pm-toolchain exception (owner rule pm-cli-website-6d05: pm bumps land unattended; required checks gate them)." +files[2]{path,scope}: + .github/dependabot.yml,project + .github/workflows/dependabot-auto-merge.yml,project +docs[1]{path,scope}: + .github/workflows/dependabot-auto-merge.yml,project +close_reason: "Rolled out the reviewed pilot (unbraind/pm-presets#118, auto-merge proven on pm-presets#119, groups made disjoint in pm-presets#120). This PR's required checks gate the merge; repository auto-merge and branch deletion enabled." +body: Fleet-wide automation of version bumps; see companion pm-cli-website-6d05. diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 2b876a3..db63021 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -3,8 +3,29 @@ updates: - package-ecosystem: "npm" directory: "/" schedule: - interval: "weekly" + interval: "daily" open-pull-requests-limit: 5 + groups: + # The pm CLI, its SDK-bearing packages and the fleet gates move together + # in one pull request per day; dependabot-auto-merge.yml merges it as soon + # as the required checks pass, so a release bump needs no manual work. + # No update-types filter: pm uses calendar versions, so a year rollover + # (2026.x -> 2027.x) is a semver major that must still land unattended. + pm-toolchain: + patterns: + - "@unbrained/pm-cli" + - "pm-*" + dependencies: + # Every other npm dependency, disjoint from pm-toolchain, so a pm + # package can never be bumped here (and capped by update-types). + patterns: + - "*" + exclude-patterns: + - "@unbrained/pm-cli" + - "pm-*" + update-types: + - "minor" + - "patch" - package-ecosystem: "github-actions" directory: "/" diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml new file mode 100644 index 0000000..85d4c77 --- /dev/null +++ b/.github/workflows/dependabot-auto-merge.yml @@ -0,0 +1,33 @@ +name: dependabot-auto-merge + +# Version bumps are mechanical: every non-major Dependabot pull request gets +# GitHub auto-merge, so it lands the moment the required checks pass. Branch +# protection still gates the merge; a failing bump stays open as a defect. +on: pull_request + +permissions: {} + +jobs: + enable-auto-merge: + if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository_owner == 'unbraind' + runs-on: ubuntu-latest + # `gh pr merge --auto` needs pull-requests: write to enable auto-merge + # and contents: write for the squash merge GitHub performs once the + # required checks pass. Nothing is checked out or executed from the PR. + permissions: + contents: write + pull-requests: write + steps: + - id: metadata + uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 + # pm-toolchain is calendar-versioned (a new year reads as semver-major), + # so it always auto-merges. Anything else must be classified minor or + # patch; a major or unclassified update waits for a person. + - if: >- + steps.metadata.outputs.dependency-group == 'pm-toolchain' || + steps.metadata.outputs.update-type == 'version-update:semver-minor' || + steps.metadata.outputs.update-type == 'version-update:semver-patch' + run: gh pr merge --auto --squash "$PR_URL" + env: + PR_URL: ${{ github.event.pull_request.html_url }} + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/CHANGELOG.md b/CHANGELOG.md index b0069b0..ff88ddc 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog +## Unreleased + +### Other + +- Auto-merge green Dependabot updates and group the pm toolchain into one daily PR ([pm-github-u9df](https://github.com/unbraind/pm-github/blob/main/.agents/pm/tasks/pm-github-u9df.toon)) + ## 2026.9.26 - 2026-09-26 ### Other