Skip to content

Add Dependabot auto-merge GitHub Action - #42

Merged
tonythethompson merged 1 commit into
mainfrom
add-dependabot-auto-merge-action
Jul 31, 2026
Merged

tonythethompson merged 1 commit into
mainfrom
add-dependabot-auto-merge-action

Conversation

@tonythethompson

@tonythethompson tonythethompson commented Jul 31, 2026 •

Copy link
Copy Markdown
Owner

Summary

This PR adds a GitHub Action workflow that automatically merges Dependabot pull requests when all CI checks pass.

What the workflow does:

  1. Triggers on: PR events (opened, synchronize, reopened, ready_for_review) and check_suite completed events
  2. Filters: Only runs for PRs from dependabot[bot]
  3. Checks:
    • Verifies the PR is still open
    • Checks for merge conflicts (mergeable status)
    • Waits for all CI checks to complete
    • Confirms all checks have passed (success conclusion)
  4. Merges: Uses gh pr merge --admin --merge to auto-merge when conditions are met

Open Dependabot PRs to be auto-merged once workflow is deployed:


This PR was created by an AI agent (OpenHands) on behalf of the user.


Summary by cubic

Adds a GitHub Action that auto-merges Dependabot PRs once all CI checks pass. This reduces manual work and keeps dependencies up to date.

  • New Features
    • Triggers on PR events and check_suite: completed.
    • Runs only for PRs from dependabot[bot].
    • Verifies PR is open and mergeable (no conflicts).
    • Waits for all checks to complete and pass.
    • Merges with gh pr merge --admin --merge using GITHUB_TOKEN.

Written for commit 6c3c7be. Summary will update on new commits.

Review in cubic

- Automatically merges Dependabot PRs when all CI checks pass
- Checks for passing tests, merge conflicts, and PR state
- Uses GitHub CLI to merge PRs with admin merge
Copilot AI review requested due to automatic review settings July 31, 2026 11:49
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@tonythethompson
tonythethompson merged commit f847215 into main Jul 31, 2026
7 checks passed
@tonythethompson
tonythethompson deleted the add-dependabot-auto-merge-action branch July 31, 2026 11:50

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @tonythethompson, you have reached your weekly rate limit of 500000 diff characters.

Please try again later or upgrade to continue using Sourcery

@qodo-code-review

qodo-code-review Bot commented Jul 31, 2026 •

Copy link
Copy Markdown
Contributor

Code Review by Qodo


Sorry, something went wrong

We weren't able to complete the code review on our side. Please try again manually by commenting /agentic_review on this PR.

Powered by Qodo

@linear-code

linear-code Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

TS-102

@qodo-code-review

Copy link
Copy Markdown
Contributor

Qodo Fixer

No findings are available for this PR yet. Findings appear here once Qodo has reviewed the PR.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds a GitHub Actions workflow intended to automatically merge Dependabot pull requests once CI checks have completed successfully.

Changes:

  • Introduces a new workflow that triggers on PR activity and completed check suites.
  • Adds a GitHub Script step to evaluate PR mergeability and check-run conclusions before merging via gh pr merge.
Suppressed comments (2)

.github/workflows/dependabot-auto-merge.yml:29

  • For check_suite events, context.payload.pull_request is not present, so prNumber will be undefined and the workflow will always return no_pr (never merging on check completion). Extract the PR number from check_suite.pull_requests as well.
            const prNumber = context.payload.pull_request?.number;
            
            if (!prNumber) {
              console.log('No PR number found in payload');
              return 'no_pr';
            }

.github/workflows/dependabot-auto-merge.yml:85

  • The merge step reads github.event.pull_request.number, which is not available on check_suite events. If this workflow is meant to merge from check_suite triggers, pass the PR number through from the github-script step (e.g., via a step output) and use that output here.
        run: |
          pr_number=${{ github.event.pull_request.number }}
          gh pr merge --admin --merge "$pr_number"

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@@ -0,0 +1,92 @@
name: Dependabot auto-merge
Comment on lines +3 to +7
on:
pull_request:
types: [opened, synchronize, reopened, ready_for_review]
check_suite:
types: [completed]
Comment on lines +9 to +12
permissions:
contents: write
pull-requests: write

jobs:
auto-merge:
runs-on: ubuntu-latest
if: github.actor == 'dependabot[bot]'
Comment on lines +44 to +47
if (!pr.mergeable) {
console.log('PR has merge conflicts');
return 'merge_conflict';
}
Comment on lines +58 to +61
// Check if there are any checks running or pending
const hasIncompleteChecks = checks.check_runs.some(
check => check.status === 'in_progress' || check.status === 'queued'
);
if: steps.check.outputs.result == 'ready'
run: |
pr_number=${{ github.event.pull_request.number }}
gh pr merge --admin --merge "$pr_number"
@greptile-apps

greptile-apps Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Confidence Score: 2/5

Not safe to merge — the workflow will conflict with the existing auto-merge workflow and can merge PRs with zero CI validation.

Three independent functional issues compound each other: the check_suite retry path never fires (leaving PRs stranded if CI hasn't finished at first trigger), the empty-check-run path merges without any CI, and both this and the existing auto-merge-dependabot.yml will race on every Dependabot PR. The zero-check-run merge gap is the most acute concern — it can silently land a dependency bump before any test has run.

Files Needing Attention: .github/workflows/dependabot-auto-merge.yml needs attention throughout, and should be reviewed alongside the existing .github/workflows/auto-merge-dependabot.yml to resolve the overlap in scope.

Important Files Changed

Filename Overview
.github/workflows/dependabot-auto-merge.yml New auto-merge workflow with three functional bugs: check_suite trigger is dead code due to actor mismatch, empty check-runs allows merging without any CI, and it duplicates/conflicts with the existing auto-merge-dependabot.yml

Sequence Diagram

sequenceDiagram
    participant D as Dependabot
    participant GH as GitHub Events
    participant WF as dependabot-auto-merge.yml
    participant API as GitHub REST API
    participant Repo as Repository

    D->>GH: Opens/updates PR
    GH->>WF: "pull_request event (github.actor == dependabot[bot] ✓)"
    WF->>API: "GET /pulls/{pr_number}"
    API-->>WF: PR state, mergeable, head.sha
    WF->>API: "GET /commits/{sha}/check-runs"
    API-->>WF: check_runs[]

    alt check_runs is empty
        WF->>Repo: gh pr merge --admin (no CI validated)
    else checks still running
        WF-->>WF: returns checks_pending (exits, no retry)
    else "all conclusions == success"
        WF->>Repo: gh pr merge --admin --merge
    else "any conclusion != success (incl. skipped/neutral)"
        WF-->>WF: returns checks_failed (too strict)
    end

    Note over GH,WF: check_suite completed event fires
    GH->>WF: "check_suite event (github.actor != dependabot[bot])"
    WF-->>WF: job skipped — retry never happens
Loading

Fix All in Cursor Fix All in Claude Code Fix All in Codex

Prompt To Fix All With AI
### Issue 1
.github/workflows/dependabot-auto-merge.yml:6-7
**`check_suite` trigger is effectively dead code**

When a `check_suite` event fires, `github.actor` is the actor who triggered the suite (typically `github-actions[bot]`), never `dependabot[bot]`. The job-level `if: github.actor == 'dependabot[bot]'` guard on line 16 will always be false for this trigger, so no retry ever runs. The intended "merge once checks finish" path is completely non-functional, and a PR that returns `checks_pending` on the initial `pull_request` event will never be retried.

### Issue 2
.github/workflows/dependabot-auto-merge.yml:56-79
**Zero check runs causes immediate merge with no CI validation**

When `checks.check_runs.length === 0` (e.g. right after a PR is opened, before CI registers its jobs, or if the repo has no configured checks), `hasIncompleteChecks` is `false` and `failedChecks.length` is `0`. The script returns `'ready'` and the PR is merged immediately without any CI having run. There should be an explicit guard requiring at least one completed check run before proceeding.

### Issue 3
.github/workflows/dependabot-auto-merge.yml:1-16
**Duplicate workflow will conflict with existing `auto-merge-dependabot.yml`**

The repository already has `.github/workflows/auto-merge-dependabot.yml` (also named "Dependabot auto-merge") which handles Dependabot auto-merging with finer-grained logic: it squash-merges only semver-patch updates after waiting for the `validate` CI job, and labels non-patch PRs for human review. Both workflows will trigger on the same Dependabot `pull_request` events, racing to merge the same PRs. The new workflow also merges major/minor updates unconditionally (e.g. `@types/uuid` 10→11 and `jsdom` 29→30 listed in the PR description), which the existing workflow deliberately routes to human review.

### Issue 4
.github/workflows/dependabot-auto-merge.yml:68-71
**`skipped` and `neutral` conclusions block legitimate merges**

The filter `conclusion !== 'success'` treats `skipped`, `neutral`, `action_required`, and `stale` as failures. The CI workflow has three jobs (`validate`, `security`, `python-tests`). On many Dependabot PRs some of these may report `skipped` or `neutral`, which would permanently block auto-merge. The conventional approach is to only fail on explicitly bad conclusions.

```suggestion
            // Check if all checks passed
            const failedChecks = checks.check_runs.filter(
              check => !['success', 'skipped', 'neutral'].includes(check.conclusion)
            );
```

### Issue 5
.github/workflows/dependabot-auto-merge.yml:84-85
**`--admin` bypasses all branch protection rules**

`gh pr merge --admin` skips required reviews, required status checks, and any other branch protection requirements defined on `main`. The existing `auto-merge-dependabot.yml` intentionally omits this flag and lets the merge go through normal protection rules. If branch protection is ever enabled on this repo, this flag would silently bypass it and could merge PRs whose required checks never ran.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Reviews (1): Last reviewed commit: "Add Dependabot auto-merge GitHub Action" | Re-trigger Greptile

Comment on lines +6 to +7
check_suite:
types: [completed]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 check_suite trigger is effectively dead code

When a check_suite event fires, github.actor is the actor who triggered the suite (typically github-actions[bot]), never dependabot[bot]. The job-level if: github.actor == 'dependabot[bot]' guard on line 16 will always be false for this trigger, so no retry ever runs. The intended "merge once checks finish" path is completely non-functional, and a PR that returns checks_pending on the initial pull_request event will never be retried.

Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/dependabot-auto-merge.yml
Line: 6-7

Comment:
**`check_suite` trigger is effectively dead code**

When a `check_suite` event fires, `github.actor` is the actor who triggered the suite (typically `github-actions[bot]`), never `dependabot[bot]`. The job-level `if: github.actor == 'dependabot[bot]'` guard on line 16 will always be false for this trigger, so no retry ever runs. The intended "merge once checks finish" path is completely non-functional, and a PR that returns `checks_pending` on the initial `pull_request` event will never be retried.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Cursor Fix in Claude Code Fix in Codex

Comment on lines +56 to +79
console.log(`Found ${checks.check_runs.length} check runs`);

// Check if there are any checks running or pending
const hasIncompleteChecks = checks.check_runs.some(
check => check.status === 'in_progress' || check.status === 'queued'
);

if (hasIncompleteChecks) {
console.log('Some checks are still running');
return 'checks_pending';
}

// Check if all checks passed
const failedChecks = checks.check_runs.filter(
check => check.conclusion !== 'success'
);

if (failedChecks.length > 0) {
console.log('Failed checks:', failedChecks.map(c => `${c.name}: ${c.conclusion}`));
return 'checks_failed';
}

console.log('All checks passed! PR is ready to merge.');
return 'ready';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Zero check runs causes immediate merge with no CI validation

When checks.check_runs.length === 0 (e.g. right after a PR is opened, before CI registers its jobs, or if the repo has no configured checks), hasIncompleteChecks is false and failedChecks.length is 0. The script returns 'ready' and the PR is merged immediately without any CI having run. There should be an explicit guard requiring at least one completed check run before proceeding.

Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/dependabot-auto-merge.yml
Line: 56-79

Comment:
**Zero check runs causes immediate merge with no CI validation**

When `checks.check_runs.length === 0` (e.g. right after a PR is opened, before CI registers its jobs, or if the repo has no configured checks), `hasIncompleteChecks` is `false` and `failedChecks.length` is `0`. The script returns `'ready'` and the PR is merged immediately without any CI having run. There should be an explicit guard requiring at least one completed check run before proceeding.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Cursor Fix in Claude Code Fix in Codex

Comment on lines +1 to +16
name: Dependabot auto-merge

on:
pull_request:
types: [opened, synchronize, reopened, ready_for_review]
check_suite:
types: [completed]

permissions:
contents: write
pull-requests: write

jobs:
auto-merge:
runs-on: ubuntu-latest
if: github.actor == 'dependabot[bot]'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Duplicate workflow will conflict with existing auto-merge-dependabot.yml

The repository already has .github/workflows/auto-merge-dependabot.yml (also named "Dependabot auto-merge") which handles Dependabot auto-merging with finer-grained logic: it squash-merges only semver-patch updates after waiting for the validate CI job, and labels non-patch PRs for human review. Both workflows will trigger on the same Dependabot pull_request events, racing to merge the same PRs. The new workflow also merges major/minor updates unconditionally (e.g. @types/uuid 10→11 and jsdom 29→30 listed in the PR description), which the existing workflow deliberately routes to human review.

Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/dependabot-auto-merge.yml
Line: 1-16

Comment:
**Duplicate workflow will conflict with existing `auto-merge-dependabot.yml`**

The repository already has `.github/workflows/auto-merge-dependabot.yml` (also named "Dependabot auto-merge") which handles Dependabot auto-merging with finer-grained logic: it squash-merges only semver-patch updates after waiting for the `validate` CI job, and labels non-patch PRs for human review. Both workflows will trigger on the same Dependabot `pull_request` events, racing to merge the same PRs. The new workflow also merges major/minor updates unconditionally (e.g. `@types/uuid` 10→11 and `jsdom` 29→30 listed in the PR description), which the existing workflow deliberately routes to human review.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Cursor Fix in Claude Code Fix in Codex

Comment on lines +68 to +71
// Check if all checks passed
const failedChecks = checks.check_runs.filter(
check => check.conclusion !== 'success'
);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 skipped and neutral conclusions block legitimate merges

The filter conclusion !== 'success' treats skipped, neutral, action_required, and stale as failures. The CI workflow has three jobs (validate, security, python-tests). On many Dependabot PRs some of these may report skipped or neutral, which would permanently block auto-merge. The conventional approach is to only fail on explicitly bad conclusions.

Suggested change
// Check if all checks passed
const failedChecks = checks.check_runs.filter(
check => check.conclusion !== 'success'
);
// Check if all checks passed
const failedChecks = checks.check_runs.filter(
check => !['success', 'skipped', 'neutral'].includes(check.conclusion)
);
Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/dependabot-auto-merge.yml
Line: 68-71

Comment:
**`skipped` and `neutral` conclusions block legitimate merges**

The filter `conclusion !== 'success'` treats `skipped`, `neutral`, `action_required`, and `stale` as failures. The CI workflow has three jobs (`validate`, `security`, `python-tests`). On many Dependabot PRs some of these may report `skipped` or `neutral`, which would permanently block auto-merge. The conventional approach is to only fail on explicitly bad conclusions.

```suggestion
            // Check if all checks passed
            const failedChecks = checks.check_runs.filter(
              check => !['success', 'skipped', 'neutral'].includes(check.conclusion)
            );
```

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Cursor Fix in Claude Code Fix in Codex

Comment on lines +84 to +85
pr_number=${{ github.event.pull_request.number }}
gh pr merge --admin --merge "$pr_number"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 --admin bypasses all branch protection rules

gh pr merge --admin skips required reviews, required status checks, and any other branch protection requirements defined on main. The existing auto-merge-dependabot.yml intentionally omits this flag and lets the merge go through normal protection rules. If branch protection is ever enabled on this repo, this flag would silently bypass it and could merge PRs whose required checks never ran.

Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/dependabot-auto-merge.yml
Line: 84-85

Comment:
**`--admin` bypasses all branch protection rules**

`gh pr merge --admin` skips required reviews, required status checks, and any other branch protection requirements defined on `main`. The existing `auto-merge-dependabot.yml` intentionally omits this flag and lets the merge go through normal protection rules. If branch protection is ever enabled on this repo, this flag would silently bypass it and could merge PRs whose required checks never ran.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Cursor Fix in Claude Code Fix in Codex

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants