Add Dependabot auto-merge GitHub Action - #42
Conversation
- Automatically merges Dependabot PRs when all CI checks pass - Checks for passing tests, merge conflicts, and PR state - Uses GitHub CLI to merge PRs with admin merge
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Sorry @tonythethompson, you have reached your weekly rate limit of 500000 diff characters.
Please try again later or upgrade to continue using Sourcery
Code Review by QodoSorry, something went wrongWe weren't able to complete the code review on our side. Please try again manually by commenting/agentic_review on this PR.
Powered by Qodo |
Qodo FixerNo findings are available for this PR yet. Findings appear here once Qodo has reviewed the PR. |
There was a problem hiding this comment.
Pull request overview
This PR adds a GitHub Actions workflow intended to automatically merge Dependabot pull requests once CI checks have completed successfully.
Changes:
- Introduces a new workflow that triggers on PR activity and completed check suites.
- Adds a GitHub Script step to evaluate PR mergeability and check-run conclusions before merging via
gh pr merge.
Suppressed comments (2)
.github/workflows/dependabot-auto-merge.yml:29
- For
check_suiteevents,context.payload.pull_requestis not present, soprNumberwill be undefined and the workflow will always returnno_pr(never merging on check completion). Extract the PR number fromcheck_suite.pull_requestsas well.
const prNumber = context.payload.pull_request?.number;
if (!prNumber) {
console.log('No PR number found in payload');
return 'no_pr';
}
.github/workflows/dependabot-auto-merge.yml:85
- The merge step reads
github.event.pull_request.number, which is not available oncheck_suiteevents. If this workflow is meant to merge fromcheck_suitetriggers, pass the PR number through from the github-script step (e.g., via a step output) and use that output here.
run: |
pr_number=${{ github.event.pull_request.number }}
gh pr merge --admin --merge "$pr_number"
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| @@ -0,0 +1,92 @@ | |||
| name: Dependabot auto-merge | |||
| on: | ||
| pull_request: | ||
| types: [opened, synchronize, reopened, ready_for_review] | ||
| check_suite: | ||
| types: [completed] |
| permissions: | ||
| contents: write | ||
| pull-requests: write | ||
|
|
| jobs: | ||
| auto-merge: | ||
| runs-on: ubuntu-latest | ||
| if: github.actor == 'dependabot[bot]' |
| if (!pr.mergeable) { | ||
| console.log('PR has merge conflicts'); | ||
| return 'merge_conflict'; | ||
| } |
| // Check if there are any checks running or pending | ||
| const hasIncompleteChecks = checks.check_runs.some( | ||
| check => check.status === 'in_progress' || check.status === 'queued' | ||
| ); |
| if: steps.check.outputs.result == 'ready' | ||
| run: | | ||
| pr_number=${{ github.event.pull_request.number }} | ||
| gh pr merge --admin --merge "$pr_number" |
|
| Filename | Overview |
|---|---|
| .github/workflows/dependabot-auto-merge.yml | New auto-merge workflow with three functional bugs: check_suite trigger is dead code due to actor mismatch, empty check-runs allows merging without any CI, and it duplicates/conflicts with the existing auto-merge-dependabot.yml |
Sequence Diagram
sequenceDiagram
participant D as Dependabot
participant GH as GitHub Events
participant WF as dependabot-auto-merge.yml
participant API as GitHub REST API
participant Repo as Repository
D->>GH: Opens/updates PR
GH->>WF: "pull_request event (github.actor == dependabot[bot] ✓)"
WF->>API: "GET /pulls/{pr_number}"
API-->>WF: PR state, mergeable, head.sha
WF->>API: "GET /commits/{sha}/check-runs"
API-->>WF: check_runs[]
alt check_runs is empty
WF->>Repo: gh pr merge --admin (no CI validated)
else checks still running
WF-->>WF: returns checks_pending (exits, no retry)
else "all conclusions == success"
WF->>Repo: gh pr merge --admin --merge
else "any conclusion != success (incl. skipped/neutral)"
WF-->>WF: returns checks_failed (too strict)
end
Note over GH,WF: check_suite completed event fires
GH->>WF: "check_suite event (github.actor != dependabot[bot])"
WF-->>WF: job skipped — retry never happens
Prompt To Fix All With AI
### Issue 1
.github/workflows/dependabot-auto-merge.yml:6-7
**`check_suite` trigger is effectively dead code**
When a `check_suite` event fires, `github.actor` is the actor who triggered the suite (typically `github-actions[bot]`), never `dependabot[bot]`. The job-level `if: github.actor == 'dependabot[bot]'` guard on line 16 will always be false for this trigger, so no retry ever runs. The intended "merge once checks finish" path is completely non-functional, and a PR that returns `checks_pending` on the initial `pull_request` event will never be retried.
### Issue 2
.github/workflows/dependabot-auto-merge.yml:56-79
**Zero check runs causes immediate merge with no CI validation**
When `checks.check_runs.length === 0` (e.g. right after a PR is opened, before CI registers its jobs, or if the repo has no configured checks), `hasIncompleteChecks` is `false` and `failedChecks.length` is `0`. The script returns `'ready'` and the PR is merged immediately without any CI having run. There should be an explicit guard requiring at least one completed check run before proceeding.
### Issue 3
.github/workflows/dependabot-auto-merge.yml:1-16
**Duplicate workflow will conflict with existing `auto-merge-dependabot.yml`**
The repository already has `.github/workflows/auto-merge-dependabot.yml` (also named "Dependabot auto-merge") which handles Dependabot auto-merging with finer-grained logic: it squash-merges only semver-patch updates after waiting for the `validate` CI job, and labels non-patch PRs for human review. Both workflows will trigger on the same Dependabot `pull_request` events, racing to merge the same PRs. The new workflow also merges major/minor updates unconditionally (e.g. `@types/uuid` 10→11 and `jsdom` 29→30 listed in the PR description), which the existing workflow deliberately routes to human review.
### Issue 4
.github/workflows/dependabot-auto-merge.yml:68-71
**`skipped` and `neutral` conclusions block legitimate merges**
The filter `conclusion !== 'success'` treats `skipped`, `neutral`, `action_required`, and `stale` as failures. The CI workflow has three jobs (`validate`, `security`, `python-tests`). On many Dependabot PRs some of these may report `skipped` or `neutral`, which would permanently block auto-merge. The conventional approach is to only fail on explicitly bad conclusions.
```suggestion
// Check if all checks passed
const failedChecks = checks.check_runs.filter(
check => !['success', 'skipped', 'neutral'].includes(check.conclusion)
);
```
### Issue 5
.github/workflows/dependabot-auto-merge.yml:84-85
**`--admin` bypasses all branch protection rules**
`gh pr merge --admin` skips required reviews, required status checks, and any other branch protection requirements defined on `main`. The existing `auto-merge-dependabot.yml` intentionally omits this flag and lets the merge go through normal protection rules. If branch protection is ever enabled on this repo, this flag would silently bypass it and could merge PRs whose required checks never ran.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.Reviews (1): Last reviewed commit: "Add Dependabot auto-merge GitHub Action" | Re-trigger Greptile
| check_suite: | ||
| types: [completed] |
There was a problem hiding this comment.
check_suite trigger is effectively dead code
When a check_suite event fires, github.actor is the actor who triggered the suite (typically github-actions[bot]), never dependabot[bot]. The job-level if: github.actor == 'dependabot[bot]' guard on line 16 will always be false for this trigger, so no retry ever runs. The intended "merge once checks finish" path is completely non-functional, and a PR that returns checks_pending on the initial pull_request event will never be retried.
Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/dependabot-auto-merge.yml
Line: 6-7
Comment:
**`check_suite` trigger is effectively dead code**
When a `check_suite` event fires, `github.actor` is the actor who triggered the suite (typically `github-actions[bot]`), never `dependabot[bot]`. The job-level `if: github.actor == 'dependabot[bot]'` guard on line 16 will always be false for this trigger, so no retry ever runs. The intended "merge once checks finish" path is completely non-functional, and a PR that returns `checks_pending` on the initial `pull_request` event will never be retried.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| console.log(`Found ${checks.check_runs.length} check runs`); | ||
|
|
||
| // Check if there are any checks running or pending | ||
| const hasIncompleteChecks = checks.check_runs.some( | ||
| check => check.status === 'in_progress' || check.status === 'queued' | ||
| ); | ||
|
|
||
| if (hasIncompleteChecks) { | ||
| console.log('Some checks are still running'); | ||
| return 'checks_pending'; | ||
| } | ||
|
|
||
| // Check if all checks passed | ||
| const failedChecks = checks.check_runs.filter( | ||
| check => check.conclusion !== 'success' | ||
| ); | ||
|
|
||
| if (failedChecks.length > 0) { | ||
| console.log('Failed checks:', failedChecks.map(c => `${c.name}: ${c.conclusion}`)); | ||
| return 'checks_failed'; | ||
| } | ||
|
|
||
| console.log('All checks passed! PR is ready to merge.'); | ||
| return 'ready'; |
There was a problem hiding this comment.
Zero check runs causes immediate merge with no CI validation
When checks.check_runs.length === 0 (e.g. right after a PR is opened, before CI registers its jobs, or if the repo has no configured checks), hasIncompleteChecks is false and failedChecks.length is 0. The script returns 'ready' and the PR is merged immediately without any CI having run. There should be an explicit guard requiring at least one completed check run before proceeding.
Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/dependabot-auto-merge.yml
Line: 56-79
Comment:
**Zero check runs causes immediate merge with no CI validation**
When `checks.check_runs.length === 0` (e.g. right after a PR is opened, before CI registers its jobs, or if the repo has no configured checks), `hasIncompleteChecks` is `false` and `failedChecks.length` is `0`. The script returns `'ready'` and the PR is merged immediately without any CI having run. There should be an explicit guard requiring at least one completed check run before proceeding.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| name: Dependabot auto-merge | ||
|
|
||
| on: | ||
| pull_request: | ||
| types: [opened, synchronize, reopened, ready_for_review] | ||
| check_suite: | ||
| types: [completed] | ||
|
|
||
| permissions: | ||
| contents: write | ||
| pull-requests: write | ||
|
|
||
| jobs: | ||
| auto-merge: | ||
| runs-on: ubuntu-latest | ||
| if: github.actor == 'dependabot[bot]' |
There was a problem hiding this comment.
Duplicate workflow will conflict with existing
auto-merge-dependabot.yml
The repository already has .github/workflows/auto-merge-dependabot.yml (also named "Dependabot auto-merge") which handles Dependabot auto-merging with finer-grained logic: it squash-merges only semver-patch updates after waiting for the validate CI job, and labels non-patch PRs for human review. Both workflows will trigger on the same Dependabot pull_request events, racing to merge the same PRs. The new workflow also merges major/minor updates unconditionally (e.g. @types/uuid 10→11 and jsdom 29→30 listed in the PR description), which the existing workflow deliberately routes to human review.
Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/dependabot-auto-merge.yml
Line: 1-16
Comment:
**Duplicate workflow will conflict with existing `auto-merge-dependabot.yml`**
The repository already has `.github/workflows/auto-merge-dependabot.yml` (also named "Dependabot auto-merge") which handles Dependabot auto-merging with finer-grained logic: it squash-merges only semver-patch updates after waiting for the `validate` CI job, and labels non-patch PRs for human review. Both workflows will trigger on the same Dependabot `pull_request` events, racing to merge the same PRs. The new workflow also merges major/minor updates unconditionally (e.g. `@types/uuid` 10→11 and `jsdom` 29→30 listed in the PR description), which the existing workflow deliberately routes to human review.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| // Check if all checks passed | ||
| const failedChecks = checks.check_runs.filter( | ||
| check => check.conclusion !== 'success' | ||
| ); |
There was a problem hiding this comment.
skipped and neutral conclusions block legitimate merges
The filter conclusion !== 'success' treats skipped, neutral, action_required, and stale as failures. The CI workflow has three jobs (validate, security, python-tests). On many Dependabot PRs some of these may report skipped or neutral, which would permanently block auto-merge. The conventional approach is to only fail on explicitly bad conclusions.
| // Check if all checks passed | |
| const failedChecks = checks.check_runs.filter( | |
| check => check.conclusion !== 'success' | |
| ); | |
| // Check if all checks passed | |
| const failedChecks = checks.check_runs.filter( | |
| check => !['success', 'skipped', 'neutral'].includes(check.conclusion) | |
| ); |
Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/dependabot-auto-merge.yml
Line: 68-71
Comment:
**`skipped` and `neutral` conclusions block legitimate merges**
The filter `conclusion !== 'success'` treats `skipped`, `neutral`, `action_required`, and `stale` as failures. The CI workflow has three jobs (`validate`, `security`, `python-tests`). On many Dependabot PRs some of these may report `skipped` or `neutral`, which would permanently block auto-merge. The conventional approach is to only fail on explicitly bad conclusions.
```suggestion
// Check if all checks passed
const failedChecks = checks.check_runs.filter(
check => !['success', 'skipped', 'neutral'].includes(check.conclusion)
);
```
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| pr_number=${{ github.event.pull_request.number }} | ||
| gh pr merge --admin --merge "$pr_number" |
There was a problem hiding this comment.
--admin bypasses all branch protection rules
gh pr merge --admin skips required reviews, required status checks, and any other branch protection requirements defined on main. The existing auto-merge-dependabot.yml intentionally omits this flag and lets the merge go through normal protection rules. If branch protection is ever enabled on this repo, this flag would silently bypass it and could merge PRs whose required checks never ran.
Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/dependabot-auto-merge.yml
Line: 84-85
Comment:
**`--admin` bypasses all branch protection rules**
`gh pr merge --admin` skips required reviews, required status checks, and any other branch protection requirements defined on `main`. The existing `auto-merge-dependabot.yml` intentionally omits this flag and lets the merge go through normal protection rules. If branch protection is ever enabled on this repo, this flag would silently bypass it and could merge PRs whose required checks never ran.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.
Summary
This PR adds a GitHub Action workflow that automatically merges Dependabot pull requests when all CI checks pass.
What the workflow does:
dependabot[bot]mergeablestatus)successconclusion)gh pr merge --admin --mergeto auto-merge when conditions are metOpen Dependabot PRs to be auto-merged once workflow is deployed:
This PR was created by an AI agent (OpenHands) on behalf of the user.
Summary by cubic
Adds a GitHub Action that auto-merges Dependabot PRs once all CI checks pass. This reduces manual work and keeps dependencies up to date.
check_suite: completed.dependabot[bot].gh pr merge --admin --mergeusingGITHUB_TOKEN.Written for commit 6c3c7be. Summary will update on new commits.