Skip to content

Commit a826102

Browse files
committed
Apply auto-merge for all dependabot PRs
1 parent 39ece6d commit a826102

1 file changed

Lines changed: 1 addition & 12 deletions

File tree

‎.github/workflows/dependabot-automerge.yml‎

Lines changed: 1 addition & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -17,25 +17,14 @@ jobs:
1717
with:
1818
github-token: "${{ secrets.GITHUB_TOKEN }}"
1919

20-
# GITHUB_TOKEN, deliberately: a review starts no workflow run and does not need to, so the
21-
# short-lived token is enough and the approval shows in the PR as the bot rather than as a
22-
# person. This needs `can_approve_pull_request_reviews` on the repository — no `permissions`
23-
# block can stand in for it, and without it GitHub refuses with "GitHub Actions is not
24-
# permitted to approve pull requests".
2520
- name: Approve patch and minor updates
2621
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
2722
run: gh pr review --approve "$PR_URL"
2823
env:
2924
PR_URL: ${{ github.event.pull_request.html_url }}
3025
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
3126

32-
# BOT_PAT here, and not GITHUB_TOKEN: auto-merge is completed on behalf of whoever enabled
33-
# it, and a push made by GITHUB_TOKEN starts no workflow runs. Enabled with GITHUB_TOKEN the
34-
# merge lands on main silently — no CI, no CodeQL, no dependency snapshot, and
35-
# update-pr-branch never wakes to rebase the remaining PRs, so the automation cuts its own
36-
# legs. A PAT is a real user, so the push behaves like any other.
37-
- name: Enable auto-merge for patch and minor updates
38-
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
27+
- name: Enable auto-merge for all PRs
3928
run: gh pr merge --auto --squash "$PR_URL"
4029
env:
4130
PR_URL: ${{ github.event.pull_request.html_url }}

0 commit comments

Comments
 (0)