Skip to content

Auto-merge green Dependabot updates and group the pm toolchain into one daily PR - #125

Merged
unbraind merged 3 commits into
mainfrom
ci/auto-merge-green-dependabot-updates
Oct 4, 2026
Merged

unbraind merged 3 commits into
mainfrom
ci/auto-merge-green-dependabot-updates

Conversation

@unbraind

@unbraind unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

What

  • .github/dependabot.yml: npm is checked daily; @unbrained/pm-cli and pm-* packages arrive as one pm-toolchain PR, other minor/patch updates as one dependencies PR. Other ecosystems are unchanged.
  • .github/workflows/dependabot-auto-merge.yml: for Dependabot PRs only (and only in unbraind), dependabot/fetch-metadata (SHA-pinned v3.1.0) classifies the update; the pm-toolchain group (calendar-versioned, so a year rollover reads as semver-major) and every other non-major update get gh pr merge --auto --squash. Workflow default permissions are {}; the job alone gets contents: write + pull-requests: write.
  • Repository setting: auto-merge allowed, merged branches deleted.

Why

Fleet rule ([companion pm-cli-website-6d05]): a pm CLI release must reach every package without a hand-written certification PR. Branch protection still requires test (22), test (26), windows-prepare-lifecycle, so nothing merges red; a bump that fails CI stays open as a real defect. Major updates still need a person. Same change as the reviewed pilot unbraind/pm-presets#118.

pm item

Summary by Sourcery

Automate the delivery of compatible Dependabot updates while keeping major upgrades subject to manual approval.

New Features:

  • Configure daily npm Dependabot updates with grouped pull requests for the pm toolchain and other minor/patch dependencies.
  • Automatically enable squash auto-merge for green, non-major Dependabot updates while leaving major or unclassified updates for manual review.

Enhancements:

  • Apply least-privilege permissions to the Dependabot auto-merge workflow and preserve required branch protection checks.

Documentation:

  • Document the Dependabot automation and pm toolchain grouping in the changelog.

Chores:

  • Record and close the associated pm task.

Summary by cubic

Automates delivery of compatible Dependabot npm updates and groups the pm toolchain into one daily PR, so version bumps land without a hand-written certification PR.

  • npm is now checked daily instead of weekly; @unbrained/pm-cli and pm-* packages are grouped into a single pm-toolchain PR and other minor/patch updates into one dependencies PR.
  • A least-privilege workflow enables squash auto-merge for the calendar-versioned pm-toolchain group (a year rollover reads as semver-major) and for updates dependabot/fetch-metadata classifies as minor or patch; unclassified updates wait for a person.
  • Branch protection still requires the test and lifecycle checks, so a failing bump stays open as a defect, and major updates still wait for a person.
  • Logs the change in the changelog and closes the associated pm item.

Written for commit 6625aa7. Summary will update on new commits.

Review in cubic

…ne daily PR

Version bumps of @unbrained/pm-cli, pm-ops and pm-changelog are mechanical.
Dependabot now checks npm daily and groups the pm toolchain (and other
minor/patch updates) into single pull requests; a least-privilege workflow
enables squash auto-merge for every non-major Dependabot PR, so it lands as
soon as the required checks pass and a failing bump stays open as a defect.

pm item: pm-graph-088p

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 15 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 40 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: e7f85ba7-f05c-4e7f-8ad0-3f26030d1b95
📥 Commits

Reviewing files that changed from the base of the PR and between 0e905e0 and 6625aa7.

📒 Files selected for processing (5)
  • .agents/pm/history/pm-graph-088p.jsonl
  • .agents/pm/tasks/pm-graph-088p.toon
  • .github/dependabot.yml
  • .github/workflows/dependabot-auto-merge.yml
  • CHANGELOG.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 7764d16c-f965-4eda-946c-af037e61b9d9
📥 Commits

Reviewing files that changed from the base of the PR and between 0e905e0 and c62eb68.

📒 Files selected for processing (5)
  • .agents/pm/history/pm-graph-088p.jsonl
  • .agents/pm/tasks/pm-graph-088p.toon
  • .github/dependabot.yml
  • .github/workflows/dependabot-auto-merge.yml
  • CHANGELOG.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • Chores
    • Dependency updates are now checked daily and grouped into a dedicated PM toolchain update and a separate group for other minor and patch updates.
    • Eligible Dependabot pull requests can be squash-merged automatically once required checks pass. Major updates outside the PM toolchain are not auto-merged.

Walkthrough

Dependabot now checks npm updates daily and groups selected packages into separate update groups. A new workflow enables squash auto-merge for eligible Dependabot pull requests. The changelog and task records document the automation and rollout.

Changes

Dependabot automation

Layer / File(s) Summary
Daily schedule and dependency groups
.github/dependabot.yml
The npm update interval changes from weekly to daily. The configuration groups @unbrained/pm-cli and pm-* as pm-toolchain, and groups other minor and patch updates as dependencies.
Conditional auto-merge and rollout records
.github/workflows/dependabot-auto-merge.yml, .agents/pm/tasks/pm-graph-088p.toon, .agents/pm/history/pm-graph-088p.jsonl, CHANGELOG.md
The workflow enables squash auto-merge for pm-toolchain updates or non-major updates. The task records and changelog describe the automation and rollout.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant Dependabot
  participant GitHubActions
  participant DependabotMetadata
  participant GitHub
  Dependabot->>GitHubActions: Open pull request triggers workflow
  GitHubActions->>DependabotMetadata: Fetch dependency metadata
  GitHubActions->>GitHub: Enable squash auto-merge when update is eligible
  GitHub->>GitHub: Required checks gate the merge
Loading

Merge Risk: ⚪ Minimal · up to c62eb

Daily grouped Dependabot updates with conditional squash auto-merge look safe to merge. Branch-protection checks still gate every merge.

Security Architecture Review

Security architecture risk: 🔵 Low · up to c62eb

The automation is restricted to Dependabot pull requests, uses narrowly scoped repository permissions, and requests auto-merge without an administrative bypass. However, effective branch protection and behavior after subsequent pull-request changes have not been verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The direct authority is repository-scoped content and pull-request modification. The merge predicate is not npm-specific: it also covers non-major GitHub Actions updates, potentially promoting changes to future CI execution as well as executable npm dependencies.

Trust Boundaries and Controls

  • inferred — The author and owner predicates restrict entry to the privileged job, while SHA pinning limits unexpected metadata-action version changes. The merge command contains no administrative bypass, but preservation of the stated required-check gate depends on effective repository settings, not this workflow alone.

Hardening Proposals

  • proposed — Validate effective branch protection and auto-merge settings as rollout prerequisites, including the required checks claimed by the PR description. This would make the security gate independently verifiable rather than relying on descriptive comments.
  • proposed — Consider explicitly allowing recognized metadata classifications and binding enablement to the classified head commit. Verify platform revocation behavior before adding cleanup logic for later ineligible heads; the current evidence does not establish an exploitable stale-eligibility condition.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main changes: enabling auto-merge for eligible Dependabot updates and grouping the pm toolchain into a daily pull request.
Description check ✅ Passed The description explains the Dependabot schedule and grouping, auto-merge conditions, required checks, and related task. It is directly related to the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Reviewer's Guide

Dependabot now checks npm dependencies daily, groups the PM toolchain separately from routine minor/patch updates, and uses a least-privilege, SHA-pinned workflow to enable squash auto-merge for green eligible updates while leaving unrelated major updates for manual review.

Sequence diagram for Dependabot auto-merge of eligible updates

sequenceDiagram
    participant Dependabot
    participant Workflow as dependabot-auto-merge
    participant Metadata as fetch-metadata
    participant GitHub as GitHub merge queue
    participant Checks as Required checks

    Dependabot->>Workflow: pull_request
    Workflow->>Metadata: fetch metadata
    Metadata-->>Workflow: dependency-group and update-type
    alt pm-toolchain or non-major update
        Workflow->>GitHub: gh pr merge --auto --squash
        GitHub->>Checks: wait for required checks
        Checks-->>GitHub: checks pass
        GitHub-->>Dependabot: squash merge PR
    else unrelated major update
        Workflow-->>Dependabot: leave PR for manual review
    end
Loading

Flow diagram for daily Dependabot update grouping

flowchart TD
    A[Daily npm Dependabot scan] --> B{PM toolchain package?}
    B -->|Yes| C[pm-toolchain PR]
    B -->|No| D{Minor or patch update?}
    D -->|Yes| E[dependencies PR]
    D -->|No| F[Un-grouped major update]
    C --> G[Eligible for auto-merge]
    E --> G
    F --> H[Manual review]
Loading

File-Level Changes

Change Details Files
Adjust Dependabot cadence and npm grouping so the PM toolchain moves together while other routine updates remain consolidated.
  • Run npm checks daily.
  • Group the PM CLI and pm-* packages into pm-toolchain.
  • Group non-PM minor and patch updates into dependencies, excluding PM packages.
  • Leave other ecosystem configuration unchanged.
.github/dependabot.yml
Add a narrowly scoped workflow that enables GitHub auto-merge for eligible Dependabot pull requests after required checks pass.
  • Restrict execution to Dependabot PRs in the unbraind organization.
  • Pin dependabot/fetch-metadata to v3.1.0 by commit SHA.
  • Auto-merge the pm-toolchain group and all non-major updates with squash merging.
  • Require human intervention for non-PM major updates.
  • Apply empty default permissions and grant only job-level contents and pull-request write access.
.github/workflows/dependabot-auto-merge.yml
Record the associated PM work item and history entries.
  • Add the pm-graph-088p task definition.
  • Add the corresponding PM history record.
.agents/pm/tasks/pm-graph-088p.toon
.agents/pm/history/pm-graph-088p.jsonl

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@greptile-apps

greptile-apps Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Enables automatic merging of dependency updates via CI workflow.

The changes since the last review appear safe to merge.

What we checked:

  • Unclassified updates stay open: No. The changed condition requires the pm-toolchain group or an exact minor or patch classification.

Summary

Adds daily npm update groups and a workflow that requests squash auto-merge for eligible Dependabot PRs.

  • The latest change explicitly selects other dependencies with patterns: ["*"].
  • Outside pm-toolchain, only updates classified as minor or patch qualify.
  • Previous finding ci: verify bun install after npm publish #1 is addressed. No new actionable issues were found in the changes since the last review.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart TD
  A[Dependabot PR in unbraind] --> B[Read update metadata]
  B --> C{pm-toolchain or classified minor or patch?}
  C -- Yes --> D[Request squash auto-merge]
  D --> E[GitHub checks merge requirements]
  C -- No --> F[Wait for a person]
Loading

Reviews (3) · Last reviewed commit: "Allow-list minor and patch updates and d..."

Comment thread .github/dependabot.yml
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai full review
@greptileai review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

…sions

Review feedback: an update that fetch-metadata cannot classify must not
auto-merge, so the condition now requires semver-minor or semver-patch
outside the calendar-versioned pm-toolchain group. The job's write scopes
are documented, the dependencies group selects every package explicitly,
and the item's acceptance criteria name the pm-toolchain exception.

pm item: pm-graph-088p
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai full review
@greptileai review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 40 minutes.

@unbraind
unbraind merged commit de3ec49 into main Oct 4, 2026
14 checks passed
@unbraind
unbraind deleted the ci/auto-merge-green-dependabot-updates branch October 4, 2026 18:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant