Skip to content

ci: add Dependabot auto-merge workflow - #37

Merged
RealDougEubanks merged 1 commit into
mainfrom
feature/dependabot-auto-merge
Sep 10, 2026
Merged

RealDougEubanks merged 1 commit into
mainfrom
feature/dependabot-auto-merge

Conversation

@RealDougEubanks

Copy link
Copy Markdown
Owner

Summary

  • Adds .github/workflows/dependabot-auto-merge.yml: when Dependabot opens a PR, this workflow queues auto-merge via gh pr merge --auto once the PR passes all required CI checks. Only patch and minor version bumps are auto-merged; major version bumps are skipped and require manual review.
  • Enabled "Allow auto-merge" on the repository settings (required for gh pr merge --auto to function).

How it works

  1. Dependabot opens a PR for a patch or minor bump.
  2. This workflow runs, reads the update type via dependabot/fetch-metadata, and calls gh pr merge --auto --merge.
  3. GitHub queues the merge — it executes automatically once every required status check (ShellCheck, Hadolint, Bats, Python tests, Docker build smoke, Trivy, gitleaks) goes green.
  4. No human action needed for routine version bumps.

Major version bumps (e.g. a base image major release) still require manual merge — breaking changes warrant a review.

On Copilot Autofix

Copilot Autofix for CodeQL is already active on this public repo. During PR review, if CodeQL finds an alert, GitHub automatically shows a Copilot-generated fix suggestion inline — no setup needed. If you accept the suggestion, it creates a commit on the PR branch. For alerts on the default branch (post-merge), clicking "Fix with Copilot" on the Security → Code scanning alerts page still requires one click; GitHub has no API to trigger fix generation headlessly.

Test plan

  • CI passes on this PR
  • After merge, open a test Dependabot PR or wait for the next scheduled run — confirm the auto-merge workflow runs and queues the merge

🤖 Generated with Claude Code

https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5

Automatically merges Dependabot PRs for patch and minor version bumps
once all required CI checks pass. Major version bumps are excluded and
require manual review.

Uses dependabot/fetch-metadata to read the update type and gh pr merge
--auto to queue the merge — GitHub only executes the merge once every
required status check is green.

Also enabled "allow_auto_merge" on the repository via the GitHub API
(required for gh pr merge --auto to work).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PhSFmsQDhrUoFR7F8EHkD5
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/dependabot/fetch-metadata 25dd0e34f4fe68f24cc83900b1fe3fe149efef98 🟢 8.2
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies🟢 3dependency not pinned by hash detected -- score normalized to 3
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
SAST🟢 10SAST tool is run on all commits

Scanned Files

  • .github/workflows/dependabot-auto-merge.yml

@RealDougEubanks
RealDougEubanks merged commit fae7f1e into main Sep 10, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant