From d8b0449d0efd2780c696af20992373fc3f9e9daa Mon Sep 17 00:00:00 2001 From: Roma Sosnovsky Date: Tue, 29 Sep 2026 11:19:30 +0300 Subject: [PATCH 1/3] #6304 Update auto-merge.yml --- .github/workflows/auto-merge.yml | 54 ++++++++++---------------------- 1 file changed, 17 insertions(+), 37 deletions(-) diff --git a/.github/workflows/auto-merge.yml b/.github/workflows/auto-merge.yml index 01cd7efa9bf..1e4908a5ed4 100644 --- a/.github/workflows/auto-merge.yml +++ b/.github/workflows/auto-merge.yml @@ -1,47 +1,27 @@ name: Auto merge -# both actions get started on PR create/update -# approve gets done right away -# merge sleeps and retries until CI finishes successfully up to 25 minutes -# not ideal, much better would be to trigger merge later, exactly whenever CI finishes. But couldn't make make it work. - -# Trigger the workflow on pull request on: - pull_request_target: + pull_request: types: - - synchronize - opened + - reopened + - synchronize jobs: - - autoapprove: - name: Approve + dependabot: + name: Approve and enable auto-merge + if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository == 'FlowCrypt/flowcrypt-browser' runs-on: ubuntu-latest steps: - - name: Auto approve - uses: hmarr/auto-approve-action@v4.0.0 # Custom action for auto approval already available on marketplace - # Perform the auto approve action only when the PR is raised by dependabot - if: github.actor == 'dependabot[bot]' || github.actor == 'dependabot-preview[bot]' - with: - # Create a personal access token and store it under the Secrets section of the particular repository - # with the key "GITHUB_ACTIONS_TOKEN" - github-token: ${{ secrets.FLOWCRYPT_ROBOT_ACCESS_TOKEN }} - - automerge: - name: Enable automerge on dependabot PRs - runs-on: ubuntu-latest - steps: - - name: Enable automerge on dependabot PRs - uses: daneden/enable-automerge-action@v1 - with: - # A personal access token that you have generated and saved in the - # repo or org’s encrypted secrets - github-token: ${{ secrets.FLOWCRYPT_ROBOT_ACCESS_TOKEN }} - - # The name of the PR author to enable automerge for - # Defaults to dependabot[bot] - allowed-author: "dependabot[bot]" + - name: Approve pull request + run: gh pr review --approve "$PR_URL" + env: + GH_TOKEN: ${{ secrets.FLOWCRYPT_ROBOT_ACCESS_TOKEN }} + PR_URL: ${{ github.event.pull_request.html_url }} - # Allowed values: MERGE | SQUASH | REBASE - # Defaults to MERGE - merge-method: SQUASH + - name: Enable squash auto-merge + run: gh pr merge --auto --squash "$PR_URL" + env: + # Keep this as a Dependabot secret so the eventual merge triggers push workflows. + GH_TOKEN: ${{ secrets.FLOWCRYPT_ROBOT_ACCESS_TOKEN }} + PR_URL: ${{ github.event.pull_request.html_url }} From 1f6b3b19bf2f9ebeab31232f5afc4b0a921ead72 Mon Sep 17 00:00:00 2001 From: Roma Sosnovsky Date: Tue, 29 Sep 2026 11:24:48 +0300 Subject: [PATCH 2/3] updates --- .github/workflows/auto-merge.yml | 2 -- 1 file changed, 2 deletions(-) diff --git a/.github/workflows/auto-merge.yml b/.github/workflows/auto-merge.yml index 1e4908a5ed4..c319af3b778 100644 --- a/.github/workflows/auto-merge.yml +++ b/.github/workflows/auto-merge.yml @@ -4,7 +4,6 @@ on: pull_request: types: - opened - - reopened - synchronize jobs: @@ -22,6 +21,5 @@ jobs: - name: Enable squash auto-merge run: gh pr merge --auto --squash "$PR_URL" env: - # Keep this as a Dependabot secret so the eventual merge triggers push workflows. GH_TOKEN: ${{ secrets.FLOWCRYPT_ROBOT_ACCESS_TOKEN }} PR_URL: ${{ github.event.pull_request.html_url }} From dbf1547507e0ac202b6a7f373f47e6112c9e5a90 Mon Sep 17 00:00:00 2001 From: Roma Sosnovsky Date: Thu, 1 Oct 2026 11:30:53 +0300 Subject: [PATCH 3/3] add github.actor check --- .github/workflows/auto-merge.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/auto-merge.yml b/.github/workflows/auto-merge.yml index c319af3b778..b4d53433b14 100644 --- a/.github/workflows/auto-merge.yml +++ b/.github/workflows/auto-merge.yml @@ -9,7 +9,7 @@ on: jobs: dependabot: name: Approve and enable auto-merge - if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository == 'FlowCrypt/flowcrypt-browser' + if: github.event.pull_request.user.login == 'dependabot[bot]' && github.actor == 'dependabot[bot]' && github.repository == 'FlowCrypt/flowcrypt-browser' runs-on: ubuntu-latest steps: - name: Approve pull request