ci(deps): auto-merge dependabot bumps via the org reusable workflow - #57
Merged
Conversation
sphragis received its first dependabot config today and immediately had six update PRs open, none of which merge themselves. This adds the auto-merger. A sixteen-line caller rather than a copy of the workflow body. forkwright/.github owns the implementation, theatron already consumes it this way, and the logic worth not duplicating is substantial: it polls for check GROUPS to appear rather than calling `gh pr checks --watch`, because --watch returns as soon as the fast checks report and would approve a PR whose gate had not started. Adopted here and NOT in koinon, epitelesis, logismos, dioptron or typikon, which also gained dependabot configs today. The workflow waits on four check groups -- gate, cargo deny, cargo audit, osv -- and FAILS when a group never reports, which is deliberate: a verification check that goes missing is the case it exists to catch. Measured against live PRs, sphragis is the only one of the six that reports all four. koinon has neither cargo audit nor osv; epitelesis and logismos have no osv; dioptron and typikon have no security workflow at all. Copying this file into those repos would not give them auto-merge, it would give them a job that times out and reports failure on every dependabot PR. The gap to close there is security scanning, not this workflow. Pinned at d5685976, the current tip. Deliberately NOT theatron's 54f1af7c, which predates the normalised check-name matching -- that older revision compared exact suffixes and could not match `osv scanner / osv-scan` against `osv-scan` in several repos.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
sphragis received its first dependabot config today (#45) and immediately had six update PRs open. Nothing merges them. This adds the auto-merger.
A caller, not a copy
Sixteen lines delegating to
forkwright/.github, the same way theatron already consumes it. The logic worth not duplicating is real — the reusable workflow polls for check groups to appear rather than callinggh pr checks --watch, because--watchreturns as soon as the fast checks report and would approve a PR whose gate had not started building yet.Why this is NOT being copied into the other five repos
koinon, epitelesis, logismos, dioptron and typikon all gained dependabot configs today too. They are deliberately excluded, and this is the part worth reading.
The reusable workflow waits on four check groups — gate,
cargo deny,cargo audit, osv — and fails when a group never reports. That is intentional: a verification check that silently goes missing is precisely the case it exists to catch.Measured against live PRs in each repo, not inferred from workflow filenames:
gate / gateosv scanner / osv-scangate / gate-attestationgate / gategate / gateCopying this file into those five would not give them auto-merge. It would give them a job that times out and reports failure on every dependabot PR — worse than having no auto-merger, because it turns a green PR red.
The gap to close there is security scanning, not this workflow. koinon has neither
cargo auditnor osv; dioptron and typikon have nosecurity.ymlat all. Tracked separately.Pin choice
Pinned at
d5685976, the current tip offorkwright/.github.Deliberately not theatron's
54f1af7c. That revision predates the normalised check-name matching: it compared exact suffixes, soendswith("osv-scan")could not match a check actually namedosv scanner / osv-scan. sphragis reports both spellings, and the current revision strips non-alphanumerics from both sides before testing containment, which matches the whole spelling class rather than the two spellings seen so far.theatron pinning a pre-fix revision is its own small drift, noted and not fixed here.