Repository navigation
Dependabot Auto-Merge #44
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Dependabot Auto-Merge | |
| on: | |
| workflow_run: | |
| workflows: ["CI"] | |
| types: [completed] | |
| permissions: | |
| actions: read | |
| contents: write | |
| pull-requests: write | |
| jobs: | |
| merge: | |
| if: github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'pull_request' | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - name: Merge successful Dependabot GitHub Actions PR | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| REPO: ${{ github.repository }} | |
| HEAD_BRANCH: ${{ github.event.workflow_run.head_branch }} | |
| run: | | |
| set -euo pipefail | |
| if [[ "$HEAD_BRANCH" != dependabot/github_actions/* ]]; then | |
| echo "Workflow run branch $HEAD_BRANCH is not a Dependabot GitHub Actions branch." | |
| exit 0 | |
| fi | |
| pr_number=$( | |
| gh pr list \ | |
| --repo "$REPO" \ | |
| --state open \ | |
| --author "app/dependabot" \ | |
| --head "$HEAD_BRANCH" \ | |
| --json number \ | |
| --jq '.[0].number // ""' | |
| ) | |
| if [ -z "$pr_number" ]; then | |
| echo "No open Dependabot GitHub Actions PR found for branch $HEAD_BRANCH." | |
| exit 0 | |
| fi | |
| state=$(gh pr view "$pr_number" --repo "$REPO" --json state --jq '.state') | |
| if [ "$state" != "OPEN" ]; then | |
| echo "PR #$pr_number is $state; nothing to merge." | |
| exit 0 | |
| fi | |
| head_oid=$(gh pr view "$pr_number" --repo "$REPO" --json headRefOid --jq '.headRefOid') | |
| gh pr merge "$pr_number" \ | |
| --repo "$REPO" \ | |
| --squash \ | |
| --delete-branch \ | |
| --match-head-commit "$head_oid" \ | |
| --subject "chore(deps): update GitHub Actions dependencies" \ | |
| --body "" |