Auto-merge green Dependabot updates and group the pm toolchain into one daily PR - #133
Conversation
…ne daily PR Version bumps of @unbrained/pm-cli, pm-ops and pm-changelog are mechanical. Dependabot now checks npm daily and groups the pm toolchain (and other minor/patch updates) into single pull requests; a least-privilege workflow enables squash auto-merge for every non-major Dependabot PR, so it lands as soon as the required checks pass and a failing bump stays open as a defect. pm item: pm-linear-1hnc
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 40 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (5)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (5)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Summary by CodeRabbit
WalkthroughDependabot now checks npm updates daily and groups toolchain packages separately from other minor and patch updates. A new workflow enables squash auto-merge for toolchain updates and non-major updates. The changelog and task records document the automation. ChangesDependabot automation
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~15 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant Dependabot
participant GitHubActions
participant GitHubCLI
participant GitHub
Dependabot->>GitHubActions: Open pull request triggers workflow
GitHubActions->>GitHubCLI: Fetch dependency metadata
GitHubCLI-->>GitHubActions: Return dependency group and version data
alt Toolchain group or non-major update
GitHubActions->>GitHubCLI: Run gh pr merge --auto --squash
GitHubCLI->>GitHub: Enable squash auto-merge
else Other major update
GitHubActions-->>GitHubActions: Skip merge command
end
Merge Risk: ⚪ Minimal · up to The configured eligibility rules appear to preserve manual review for other major updates. No confirmed merge-blocking issue remains. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The automation is narrowly restricted to Dependabot-authored pull requests and does not execute pull-request code in the merge job. It intentionally removes manual approval for eligible updates, including major toolchain updates. The required branch protections and effective token permissions could not be independently verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideThis PR changes npm Dependabot to run daily with separate PM toolchain and general dependency groups, then adds a tightly scoped, SHA-pinned workflow that auto-enables squash merging for green eligible updates while preserving manual review for non-PM major updates; repository auto-merge and branch-deletion settings are also enabled. Sequence diagram for Dependabot auto-merge eligibilitysequenceDiagram
participant Dependabot
participant GitHub
participant Workflow
participant Metadata
participant Checks
Dependabot->>GitHub: Open pull request
GitHub->>Workflow: pull_request event
Workflow->>Workflow: Check Dependabot owner and unbraind repository
Workflow->>Metadata: fetch-metadata
Metadata-->>Workflow: dependency-group and update-type
alt pm-toolchain group or non-major update
Workflow->>GitHub: gh pr merge --auto --squash
GitHub->>Checks: Wait for required checks
Checks-->>GitHub: Checks pass
GitHub-->>Dependabot: Squash merge pull request
else Other major update
Workflow-->>Dependabot: Leave pull request for manual review
end
Flow diagram for daily Dependabot groupingflowchart LR
NPM[Daily npm scan] --> PM[pm-toolchain group]
NPM --> DEP[dependencies group]
PM --> PMPKG["@unbrained/pm-cli and pm-*"]
DEP --> OTHER[Other minor and patch updates]
PMPKG --> PR1[One daily pull request]
OTHER --> PR2[One daily pull request]
PR1 --> MERGE[Auto-merge after required checks]
PR2 --> MERGE
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
pm item: pm-linear-1hnc
|
@coderabbitai full review |
✅ Action performedFull review finished. |
…sions Review feedback: an update that fetch-metadata cannot classify must not auto-merge, so the condition now requires semver-minor or semver-patch outside the calendar-versioned pm-toolchain group. The job's write scopes are documented, the dependencies group selects every package explicitly, and the item's acceptance criteria name the pm-toolchain exception. pm item: pm-linear-1hnc
|
@coderabbitai full review |
|
What
.github/dependabot.yml: npm is checked daily;@unbrained/pm-cliandpm-*packages arrive as onepm-toolchainPR, other minor/patch updates as onedependenciesPR. Other ecosystems are unchanged..github/workflows/dependabot-auto-merge.yml: for Dependabot PRs only (and only inunbraind),dependabot/fetch-metadata(SHA-pinned v3.1.0) classifies the update; thepm-toolchaingroup (calendar-versioned, so a year rollover reads as semver-major) and every other non-major update getgh pr merge --auto --squash. Workflow default permissions are{}; the job alone getscontents: write+pull-requests: write.Why
Fleet rule ([companion pm-cli-website-6d05]): a pm CLI release must reach every package without a hand-written certification PR. Branch protection still requires
test (22),test (26), so nothing merges red; a bump that fails CI stays open as a real defect. Major updates still need a person. Same change as the reviewed pilot unbraind/pm-presets#118.pm item
Summary by Sourcery
Automate the delivery of green Dependabot updates while grouping daily pm toolchain releases into a single pull request.
New Features:
Enhancements:
CI:
Documentation:
Chores:
Summary by cubic
Automates green Dependabot updates so pm toolchain version bumps land without hand-written certification PRs.
CI automation
@unbrained/pm-clipluspm-*packages into onepm-toolchainPR; other minor/patch updates arrive as a singledependenciesPR.pm-toolchaingroup (year rollovers read as semver-major) and otherwise only for updates classified minor or patch; an unclassified update waits for a person.test (22)andtest (26), so failing bumps stay open as defects; unrelated major updates still need a person.unbraind/pm-presets#118.pm-linear-1hnc, and a changelog entry.Written for commit b1a9b53. Summary will update on new commits.