Skip to content

Auto-merge green Dependabot updates and group the pm toolchain into one daily PR - #133

Merged
unbraind merged 3 commits into
mainfrom
ci/auto-merge-green-dependabot-updates
Oct 4, 2026
Merged

unbraind merged 3 commits into
mainfrom
ci/auto-merge-green-dependabot-updates

Conversation

@unbraind

@unbraind unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

What

  • .github/dependabot.yml: npm is checked daily; @unbrained/pm-cli and pm-* packages arrive as one pm-toolchain PR, other minor/patch updates as one dependencies PR. Other ecosystems are unchanged.
  • .github/workflows/dependabot-auto-merge.yml: for Dependabot PRs only (and only in unbraind), dependabot/fetch-metadata (SHA-pinned v3.1.0) classifies the update; the pm-toolchain group (calendar-versioned, so a year rollover reads as semver-major) and every other non-major update get gh pr merge --auto --squash. Workflow default permissions are {}; the job alone gets contents: write + pull-requests: write.
  • Repository setting: auto-merge allowed, merged branches deleted.

Why

Fleet rule ([companion pm-cli-website-6d05]): a pm CLI release must reach every package without a hand-written certification PR. Branch protection still requires test (22), test (26), so nothing merges red; a bump that fails CI stays open as a real defect. Major updates still need a person. Same change as the reviewed pilot unbraind/pm-presets#118.

pm item

Summary by Sourcery

Automate the delivery of green Dependabot updates while grouping daily pm toolchain releases into a single pull request.

New Features:

  • Automate squash auto-merging of eligible green Dependabot pull requests while leaving major or unclassified updates for manual review.
  • Group the pm CLI toolchain and related packages into a daily Dependabot pull request, alongside a grouped stream for other minor and patch npm updates.

Enhancements:

  • Use least-privilege permissions and pin the Dependabot metadata action used by the auto-merge workflow.

CI:

  • Add a Dependabot auto-merge workflow gated by repository ownership, Dependabot authorship, and required status checks.

Documentation:

  • Document the Dependabot automation and toolchain grouping in the unreleased changelog.

Chores:

  • Record the associated pm task and history entries.

Summary by cubic

Automates green Dependabot updates so pm toolchain version bumps land without hand-written certification PRs.

CI automation

  • npm is now checked daily and groups @unbrained/pm-cli plus pm-* packages into one pm-toolchain PR; other minor/patch updates arrive as a single dependencies PR.
  • A least-privilege workflow enables squash auto-merge for the calendar-versioned pm-toolchain group (year rollovers read as semver-major) and otherwise only for updates classified minor or patch; an unclassified update waits for a person.
  • Branch protection still requires test (22) and test (26), so failing bumps stay open as defects; unrelated major updates still need a person.
  • Requires enabling repo auto-merge and deleting merged branches; same approach as the reviewed pilot unbraind/pm-presets#118.
  • Pairs with the closed pm item, pm-linear-1hnc, and a changelog entry.

Written for commit b1a9b53. Summary will update on new commits.

Review in cubic

…ne daily PR

Version bumps of @unbrained/pm-cli, pm-ops and pm-changelog are mechanical.
Dependabot now checks npm daily and groups the pm toolchain (and other
minor/patch updates) into single pull requests; a least-privilege workflow
enables squash auto-merge for every non-major Dependabot PR, so it lands as
soon as the required checks pass and a failing bump stays open as a defect.

pm item: pm-linear-1hnc

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 15 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 40 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 092b97de-7595-479b-9630-d86fae479fff
📥 Commits

Reviewing files that changed from the base of the PR and between 9bf2dfb and b1a9b53.

📒 Files selected for processing (5)
  • .agents/pm/history/pm-linear-1hnc.jsonl
  • .agents/pm/tasks/pm-linear-1hnc.toon
  • .github/dependabot.yml
  • .github/workflows/dependabot-auto-merge.yml
  • CHANGELOG.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 82c0afad-ad51-470a-9027-11138f8a3851
📥 Commits

Reviewing files that changed from the base of the PR and between 9bf2dfb and df353fc.

📒 Files selected for processing (5)
  • .agents/pm/history/pm-linear-1hnc.jsonl
  • .agents/pm/tasks/pm-linear-1hnc.toon
  • .github/dependabot.yml
  • .github/workflows/dependabot-auto-merge.yml
  • CHANGELOG.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • New Features
    • Dependabot now checks for npm updates daily and groups toolchain updates separately from other minor and patch updates.
    • Eligible updates can be squash-merged automatically once required checks pass. Major updates outside the toolchain group are not auto-merged.
  • Documentation
    • Added a changelog entry describing the automated update process.

Walkthrough

Dependabot now checks npm updates daily and groups toolchain packages separately from other minor and patch updates. A new workflow enables squash auto-merge for toolchain updates and non-major updates. The changelog and task records document the automation.

Changes

Dependabot automation

Layer / File(s) Summary
Schedule and update groups
.agents/pm/tasks/pm-linear-1hnc.toon, .agents/pm/history/pm-linear-1hnc.jsonl, .github/dependabot.yml
The npm schedule changes from weekly to daily. The pm-toolchain group includes @unbrained/pm-cli and pm-*; the dependencies group excludes those packages and includes minor and patch updates. Task records capture the requirements and lifecycle.
Conditional auto-merge
.github/workflows/dependabot-auto-merge.yml, CHANGELOG.md
The workflow runs for Dependabot pull requests. It enables squash auto-merge for pm-toolchain updates or non-major updates, and skips other major updates. The changelog records the automation.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~15 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant Dependabot
  participant GitHubActions
  participant GitHubCLI
  participant GitHub
  Dependabot->>GitHubActions: Open pull request triggers workflow
  GitHubActions->>GitHubCLI: Fetch dependency metadata
  GitHubCLI-->>GitHubActions: Return dependency group and version data
  alt Toolchain group or non-major update
    GitHubActions->>GitHubCLI: Run gh pr merge --auto --squash
    GitHubCLI->>GitHub: Enable squash auto-merge
  else Other major update
    GitHubActions-->>GitHubActions: Skip merge command
  end
Loading

Merge Risk: ⚪ Minimal · up to df353

The configured eligibility rules appear to preserve manual review for other major updates. No confirmed merge-blocking issue remains.

Security Architecture Review

Security architecture risk: 🔵 Low · up to df353

The automation is narrowly restricted to Dependabot-authored pull requests and does not execute pull-request code in the merge job. It intentionally removes manual approval for eligible updates, including major toolchain updates. The required branch protections and effective token permissions could not be independently verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The direct authority concerns merging eligible dependency pull requests in the repository running this workflow. Compared with the documented base behavior, these updates can be admitted without manual certification if GitHub permits the merge. Downstream runtime, deployment, tenant, and credential exposure is not established by the inspected evidence.

Trust Boundaries and Controls

  • observed — The visible boundary separates eligible Dependabot-authored pull requests from other authors before the merge command runs. A pinned metadata action determines eligibility, and the event URL is not interpolated directly into shell source. Required branch checks are described as the final control, but their actual configuration is unverified.

Resilience and Maintainability Implications

  • inferred — The visible transition consists of metadata classification followed by one external merge request; there are no local reservations or compensating steps. A failure before that command cannot create a merge request through this workflow. After submission, interruption, repetition, pull-request updates, and recovery depend on GitHub behavior that was not independently verified.

Hardening Proposals

  • proposed — Verify effective token permissions, required checks, and bypass rules with a controlled Dependabot run. Document rollback ownership, including reviewing and disabling pending auto-merge requests rather than assuming removal of the workflow revokes them.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main changes: automatic merging of eligible Dependabot updates and daily grouping of the pm toolchain.
Description check ✅ Passed The description explains the Dependabot schedule, update grouping, auto-merge rules, permissions, and required checks. It is directly related to the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR changes npm Dependabot to run daily with separate PM toolchain and general dependency groups, then adds a tightly scoped, SHA-pinned workflow that auto-enables squash merging for green eligible updates while preserving manual review for non-PM major updates; repository auto-merge and branch-deletion settings are also enabled.

Sequence diagram for Dependabot auto-merge eligibility

sequenceDiagram
    participant Dependabot
    participant GitHub
    participant Workflow
    participant Metadata
    participant Checks

    Dependabot->>GitHub: Open pull request
    GitHub->>Workflow: pull_request event
    Workflow->>Workflow: Check Dependabot owner and unbraind repository
    Workflow->>Metadata: fetch-metadata
    Metadata-->>Workflow: dependency-group and update-type
    alt pm-toolchain group or non-major update
        Workflow->>GitHub: gh pr merge --auto --squash
        GitHub->>Checks: Wait for required checks
        Checks-->>GitHub: Checks pass
        GitHub-->>Dependabot: Squash merge pull request
    else Other major update
        Workflow-->>Dependabot: Leave pull request for manual review
    end
Loading

Flow diagram for daily Dependabot grouping

flowchart LR
    NPM[Daily npm scan] --> PM[pm-toolchain group]
    NPM --> DEP[dependencies group]
    PM --> PMPKG["@unbrained/pm-cli and pm-*"]
    DEP --> OTHER[Other minor and patch updates]
    PMPKG --> PR1[One daily pull request]
    OTHER --> PR2[One daily pull request]
    PR1 --> MERGE[Auto-merge after required checks]
    PR2 --> MERGE
Loading

File-Level Changes

Change Details Files
Configure daily npm Dependabot updates with dedicated grouping for the PM toolchain and minor/patch dependencies.
  • Increase npm checks from weekly to daily.
  • Group @unbrained/pm-cli and pm-* packages into pm-toolchain.
  • Group all other minor and patch updates into dependencies while excluding PM packages.
  • Leave other ecosystem configuration unchanged.
.github/dependabot.yml
Add a least-privilege workflow that enables squash auto-merge for eligible Dependabot pull requests.
  • Restrict execution to Dependabot pull requests in the unbraind organization.
  • Fetch dependency metadata using a SHA-pinned action.
  • Auto-merge the pm-toolchain group and all non-major updates; leave other major updates for manual review.
  • Set workflow-wide permissions to none and grant write access only to the merge job.
.github/workflows/dependabot-auto-merge.yml
Record the associated PM task and history artifacts.
  • Add the task definition and JSONL history entry for pm-linear-1hnc.
.agents/pm/tasks/pm-linear-1hnc.toon
.agents/pm/history/pm-linear-1hnc.jsonl

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@greptile-apps

greptile-apps Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Enables automatic merging of dependency updates via CI workflow.

The changes since the last review appear safe to merge.

What we checked:

  • Unclassified updates stay open: The workflow accepts only the exact minor and patch values outside pm-toolchain. An empty or unknown value matches neither condition.

Summary

This PR groups daily npm updates and enables squash auto-merge for eligible Dependabot PRs.

  • The latest changes explicitly match all other npm dependencies while excluding the toolchain packages.
  • Outside pm-toolchain, only updates classified as minor or patch receive auto-merge.
  • Task records now describe that policy. No actionable new issues were found.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart TD
  A[Pull request event] --> B{Dependabot author and unbraind owner?}
  B -->|No| C[Skip job]
  B -->|Yes| D[Read update metadata]
  D --> E{pm-toolchain group or minor or patch?}
  E -->|No| F[Leave for manual review]
  E -->|Yes| G[Enable squash auto-merge]
  G --> H[GitHub applies repository merge requirements]
Loading

Reviews (3) · Last reviewed commit: "Allow-list minor and patch updates and d..."

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai full review
@greptileai review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

…sions

Review feedback: an update that fetch-metadata cannot classify must not
auto-merge, so the condition now requires semver-minor or semver-patch
outside the calendar-versioned pm-toolchain group. The job's write scopes
are documented, the dependencies group selects every package explicitly,
and the item's acceptance criteria name the pm-toolchain exception.

pm item: pm-linear-1hnc
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai full review
@greptileai review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 40 minutes.

@unbraind
unbraind merged commit 55ed55f into main Oct 4, 2026
12 checks passed
@unbraind
unbraind deleted the ci/auto-merge-green-dependabot-updates branch October 4, 2026 18:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant