ci(pr-compliance): skip PR template enforcement for dependabot - #75
Merged
Conversation
Dependabot cannot fill out the human PR template, so the compliance check is always red on its PRs, blocking routine dependency merges. Skip the job when the PR author is dependabot[bot].
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Linked Issue (Required)
N/A — unblocks routine dependency maintenance.
Problem and User Value (Required)
Dependabot PRs cannot satisfy the human-authored PR template (linked issue, scope declaration, contributor acknowledgements), so
Enforce PR template and issue-first policyis always red on them. This blocks merging of otherwise-safe dependency updates (#74, #73, #70, #68).Solution Summary (Required)
Add a job-level
if:that skips compliance enforcement whengithub.event.pull_request.user.login == 'dependabot[bot]'. Dependabot updates remain subject to all other checks (tests, lint, bundler-audit, dependency-review, gitleaks, CodeQL).Verification (Required)
Workflow YAML change only. Existing green CI on the dependabot PRs shows all other checks are the real signal.
Scope Declaration (Required)
Single-line CI workflow change.
Contributor Acknowledgements (Required)
CONTRIBUTING.md.CODE_OF_CONDUCT.md.