Skip to content

Dependabot Auto-Merge #44

Dependabot Auto-Merge

Dependabot Auto-Merge #44

name: Dependabot Auto-Merge
on:
workflow_run:
workflows: ["CI"]
types: [completed]
permissions:
actions: read
contents: write
pull-requests: write
jobs:
merge:
if: github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.event == 'pull_request'
runs-on: ubuntu-24.04
steps:
- name: Merge successful Dependabot GitHub Actions PR
env:
GH_TOKEN: ${{ github.token }}
REPO: ${{ github.repository }}
HEAD_BRANCH: ${{ github.event.workflow_run.head_branch }}
run: |
set -euo pipefail
if [[ "$HEAD_BRANCH" != dependabot/github_actions/* ]]; then
echo "Workflow run branch $HEAD_BRANCH is not a Dependabot GitHub Actions branch."
exit 0
fi
pr_number=$(
gh pr list \
--repo "$REPO" \
--state open \
--author "app/dependabot" \
--head "$HEAD_BRANCH" \
--json number \
--jq '.[0].number // ""'
)
if [ -z "$pr_number" ]; then
echo "No open Dependabot GitHub Actions PR found for branch $HEAD_BRANCH."
exit 0
fi
state=$(gh pr view "$pr_number" --repo "$REPO" --json state --jq '.state')
if [ "$state" != "OPEN" ]; then
echo "PR #$pr_number is $state; nothing to merge."
exit 0
fi
head_oid=$(gh pr view "$pr_number" --repo "$REPO" --json headRefOid --jq '.headRefOid')
gh pr merge "$pr_number" \
--repo "$REPO" \
--squash \
--delete-branch \
--match-head-commit "$head_oid" \
--subject "chore(deps): update GitHub Actions dependencies" \
--body ""