Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .agents/pm/history/pm-github-u9df.jsonl
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
{"hash_algorithm":"sha256","ts":"2026-10-04T16:54:44.174Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"create","patch":[{"op":"replace","path":"/body","value":"Fleet-wide automation of version bumps; see companion pm-cli-website-6d05."},{"op":"add","path":"/metadata/id","value":"pm-github-u9df"},{"op":"add","path":"/metadata/title","value":"Auto-merge green Dependabot updates and group the pm toolchain into one daily PR"},{"op":"add","path":"/metadata/description","value":"Version bumps of the pm CLI, SDK-bearing packages and fleet gates are mechanical and must land without a hand-written certification PR. Dependabot checks npm daily, groups @unbrained/pm-cli and pm-* packages into one pm-toolchain PR and other minor/patch updates into one dependencies PR; a least-privilege workflow enables GitHub squash auto-merge for every non-major Dependabot PR so it merges as soon as the required checks pass. A failing bump is a real defect to fix. Fleet rule: companion pm-cli-website-6d05; pilot unbraind/pm-presets#118."},{"op":"add","path":"/metadata/type","value":"Task"},{"op":"add","path":"/metadata/status","value":"open"},{"op":"add","path":"/metadata/priority","value":2},{"op":"add","path":"/metadata/tags","value":["automation","ci","dependencies"]},{"op":"add","path":"/metadata/created_at","value":"2026-10-04T16:54:44.174Z"},{"op":"add","path":"/metadata/updated_at","value":"2026-10-04T16:54:44.174Z"},{"op":"add","path":"/metadata/deadline","value":"2026-10-06T00:00:00.000Z"},{"op":"add","path":"/metadata/assignee","value":"claude-orchestrator"},{"op":"add","path":"/metadata/author","value":"claude-orchestrator"},{"op":"add","path":"/metadata/estimated_minutes","value":15},{"op":"add","path":"/metadata/acceptance_criteria","value":"dependabot.yml checks npm daily with pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge only for Dependabot non-major updates with least-privilege permissions; repository allows auto-merge; required checks still gate every merge"},{"op":"add","path":"/metadata/comments","value":[{"created_at":"2026-10-04T16:54:44.174Z","author":"claude-orchestrator","text":"Rolled out from the reviewed pilot unbraind/pm-presets#118."}]},{"op":"add","path":"/metadata/files","value":[{"path":".github/dependabot.yml","scope":"project"},{"path":".github/workflows/dependabot-auto-merge.yml","scope":"project"}]},{"op":"add","path":"/metadata/docs","value":[{"path":".github/workflows/dependabot-auto-merge.yml","scope":"project"}]}],"before_hash":"3cc22dff72be7b14824654a7a64ea62b04799939b2fee54c1b5f52ca60bf6df0","after_hash":"56745bd2b9327db77cf1526ec0b144671215a0309e265c204b7f3cb23e7db7fc","item_hash_version":3,"message":"Create item for Dependabot auto-merge | explicit_unset=dependencies,learnings,notes,tests","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"dab325a1a90617b733c0f3ae43d1643fc023f170443d837195f7d9fe29e83379"}
{"hash_algorithm":"sha256","ts":"2026-10-04T16:54:44.953Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"claim","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:54:44.953Z"},{"op":"add","path":"/metadata/claim_principal","value":"claude-orchestrator"}],"before_hash":"56745bd2b9327db77cf1526ec0b144671215a0309e265c204b7f3cb23e7db7fc","after_hash":"89e961d7bdaab4b7437b034978674b447c815488d11932bd07e0fd7b9f443708","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"d27af742dc8181ee9d3c08bc6241427962ca0a9d45bd2f006c0675c456932531"}
{"hash_algorithm":"sha256","ts":"2026-10-04T16:54:45.783Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:54:45.783Z"},{"op":"replace","path":"/metadata/status","value":"in_progress"}],"before_hash":"89e961d7bdaab4b7437b034978674b447c815488d11932bd07e0fd7b9f443708","after_hash":"6a44b0d7ac85d905d1db638199bcd222de7c0612f547a5e42d9078e09b9c299d","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"d72cacb324c4091cb87ea7f8a8467b25d46473b7f787b323b9b0d937274a5b19"}
{"hash_algorithm":"sha256","ts":"2026-10-04T16:58:39.102Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"close","patch":[{"op":"remove","path":"/metadata/assignee"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:58:39.102Z"},{"op":"replace","path":"/metadata/status","value":"closed"},{"op":"add","path":"/metadata/closed_at","value":"2026-10-04T16:58:38.805Z"},{"op":"add","path":"/metadata/completed_at","value":"2026-10-04T16:58:38.805Z"},{"op":"add","path":"/metadata/close_reason","value":"Rolled out the reviewed pilot (unbraind/pm-presets#118, auto-merge proven on pm-presets#119, groups made disjoint in pm-presets#120). This PR's required checks gate the merge; repository auto-merge and branch deletion enabled."}],"before_hash":"6a44b0d7ac85d905d1db638199bcd222de7c0612f547a5e42d9078e09b9c299d","after_hash":"b033c0c7daccef4a863755047368f8703e78b525e8babd6e222a2140281c9b53","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"ccf3a24cbbdc5f2f205670e41b4154c0a644b4e472b29aad8dafea6b64f8fe2d"}
{"hash_algorithm":"sha256","ts":"2026-10-04T16:58:45.378Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"release","patch":[{"op":"remove","path":"/metadata/claim_principal"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T16:58:45.378Z"}],"before_hash":"b033c0c7daccef4a863755047368f8703e78b525e8babd6e222a2140281c9b53","after_hash":"ead6aded286bd1eb764b5663c86cb83e2e8ff1f2ce14320959deec08338a4279","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"maintenance","record_hash_version":1,"record_hash":"5b056fb1ca9c9216bdf6a6c3502bf313ba40cf357b739cea4df194f76f728263"}
{"hash_algorithm":"sha256","ts":"2026-10-04T17:20:34.300Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"update","patch":[{"op":"replace","path":"/metadata/acceptance_criteria","value":"dependabot.yml checks npm daily with disjoint pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge for the calendar-versioned pm-toolchain group (year rollovers read as semver-major) and otherwise only for updates classified minor or patch, with documented least-privilege permissions; repository allows auto-merge; required checks still gate every merge"},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T17:20:34.300Z"}],"before_hash":"ead6aded286bd1eb764b5663c86cb83e2e8ff1f2ce14320959deec08338a4279","after_hash":"04dc48a8bf6f8a795477c2a5747499f110014fbc06b2b36ae8919f3b363f1590","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"1913931dbfe3188242a4af2ba274b3394456c0de7667fb8f731dd4387bf93fbc"}
{"hash_algorithm":"sha256","ts":"2026-10-04T17:20:40.427Z","author":"claude-orchestrator","author_source":"asserted","agent_harness":"claude-code","agent_model":"claude-opus-5-5","agent_model_source":"probe","agent_instance":"4b273145923a68729ab394ab","agent_provenance":{"model":{"value":"claude-opus-5-5","source":"probe"},"effort":{"value":"high","source":"environment"},"role":null,"topic":null,"version":{"value":"2.1.289","source":"probe"}},"op":"comment_add","patch":[{"op":"add","path":"/metadata/comments/1","value":{"created_at":"2026-10-04T17:20:40.427Z","author":"claude-orchestrator","text":"Review round 2 (Greptile/CodeRabbit across the fleet rollout): explicit minor/patch allow-list so an unclassified update never auto-merges; documented why the job needs write permissions; explicit patterns for the dependencies group; acceptance criteria now name the pm-toolchain calendar-version exception. Refused: switching to pull_request_target (GitHub keeps Dependabot-authored runs read-only there too; the pull_request + permissions pattern is proven by pm-presets#119) and removing the pm-toolchain exception (owner rule pm-cli-website-6d05: pm bumps land unattended; required checks gate them)."}},{"op":"replace","path":"/metadata/updated_at","value":"2026-10-04T17:20:40.427Z"}],"before_hash":"04dc48a8bf6f8a795477c2a5747499f110014fbc06b2b36ae8919f3b363f1590","after_hash":"8da90c032ff012191c949f713edc123054c744e10990ebd78cb60963a1ae6b80","item_hash_version":3,"context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"resolved","resolver":"claude_session_file","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"fb085bab6a15b6cb5060de7f2abf0d1edac7ed568cd8f6cf270a81786b222e8f"}
25 changes: 25 additions & 0 deletions .agents/pm/tasks/pm-github-u9df.toon
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
id: pm-github-u9df
title: Auto-merge green Dependabot updates and group the pm toolchain into one daily PR
description: "Version bumps of the pm CLI, SDK-bearing packages and fleet gates are mechanical and must land without a hand-written certification PR. Dependabot checks npm daily, groups @unbrained/pm-cli and pm-* packages into one pm-toolchain PR and other minor/patch updates into one dependencies PR; a least-privilege workflow enables GitHub squash auto-merge for every non-major Dependabot PR so it merges as soon as the required checks pass. A failing bump is a real defect to fix. Fleet rule: companion pm-cli-website-6d05; pilot unbraind/pm-presets#118."
type: Task
status: closed
priority: 2
tags[3]: automation,ci,dependencies
created_at: "2026-10-04T16:54:44.174Z"
updated_at: "2026-10-04T17:20:40.427Z"
deadline: "2026-10-06T00:00:00.000Z"
closed_at: "2026-10-04T16:58:38.805Z"
completed_at: "2026-10-04T16:58:38.805Z"
author: claude-orchestrator
estimated_minutes: 15
acceptance_criteria: "dependabot.yml checks npm daily with disjoint pm-toolchain and dependencies groups; dependabot-auto-merge.yml enables squash auto-merge for the calendar-versioned pm-toolchain group (year rollovers read as semver-major) and otherwise only for updates classified minor or patch, with documented least-privilege permissions; repository allows auto-merge; required checks still gate every merge"
comments[2]{created_at,author,text}:
"2026-10-04T16:54:44.174Z",claude-orchestrator,Rolled out from the reviewed pilot unbraind/pm-presets#118.
"2026-10-04T17:20:40.427Z",claude-orchestrator,"Review round 2 (Greptile/CodeRabbit across the fleet rollout): explicit minor/patch allow-list so an unclassified update never auto-merges; documented why the job needs write permissions; explicit patterns for the dependencies group; acceptance criteria now name the pm-toolchain calendar-version exception. Refused: switching to pull_request_target (GitHub keeps Dependabot-authored runs read-only there too; the pull_request + permissions pattern is proven by pm-presets#119) and removing the pm-toolchain exception (owner rule pm-cli-website-6d05: pm bumps land unattended; required checks gate them)."
files[2]{path,scope}:
.github/dependabot.yml,project
.github/workflows/dependabot-auto-merge.yml,project
docs[1]{path,scope}:
.github/workflows/dependabot-auto-merge.yml,project
close_reason: "Rolled out the reviewed pilot (unbraind/pm-presets#118, auto-merge proven on pm-presets#119, groups made disjoint in pm-presets#120). This PR's required checks gate the merge; repository auto-merge and branch deletion enabled."
body: Fleet-wide automation of version bumps; see companion pm-cli-website-6d05.
23 changes: 22 additions & 1 deletion .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,29 @@ updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
interval: "daily"
open-pull-requests-limit: 5
groups:
# The pm CLI, its SDK-bearing packages and the fleet gates move together
# in one pull request per day; dependabot-auto-merge.yml merges it as soon
# as the required checks pass, so a release bump needs no manual work.
# No update-types filter: pm uses calendar versions, so a year rollover
# (2026.x -> 2027.x) is a semver major that must still land unattended.
pm-toolchain:
patterns:
- "@unbrained/pm-cli"
- "pm-*"
dependencies:
# Every other npm dependency, disjoint from pm-toolchain, so a pm
# package can never be bumped here (and capped by update-types).
patterns:
- "*"
exclude-patterns:
- "@unbrained/pm-cli"
- "pm-*"
update-types:
- "minor"
- "patch"

- package-ecosystem: "github-actions"
directory: "/"
Expand Down
33 changes: 33 additions & 0 deletions .github/workflows/dependabot-auto-merge.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
name: dependabot-auto-merge

# Version bumps are mechanical: every non-major Dependabot pull request gets
# GitHub auto-merge, so it lands the moment the required checks pass. Branch
# protection still gates the merge; a failing bump stays open as a defect.
on: pull_request
Comment thread
coderabbitai[bot] marked this conversation as resolved.

permissions: {}

jobs:
enable-auto-merge:
if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository_owner == 'unbraind'
runs-on: ubuntu-latest
# `gh pr merge --auto` needs pull-requests: write to enable auto-merge
# and contents: write for the squash merge GitHub performs once the
# required checks pass. Nothing is checked out or executed from the PR.
permissions:
contents: write
pull-requests: write
steps:
- id: metadata
uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0
# pm-toolchain is calendar-versioned (a new year reads as semver-major),
# so it always auto-merges. Anything else must be classified minor or
# patch; a major or unclassified update waits for a person.
- if: >-
steps.metadata.outputs.dependency-group == 'pm-toolchain' ||
steps.metadata.outputs.update-type == 'version-update:semver-minor' ||
steps.metadata.outputs.update-type == 'version-update:semver-patch'
run: gh pr merge --auto --squash "$PR_URL"
env:
PR_URL: ${{ github.event.pull_request.html_url }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,11 @@
# Changelog

## Unreleased

### Other

- Auto-merge green Dependabot updates and group the pm toolchain into one daily PR ([pm-github-u9df](https://github.com/unbraind/pm-github/blob/main/.agents/pm/tasks/pm-github-u9df.toon))

## 2026.9.26 - 2026-09-26

### Other
Expand Down
Loading