From 4175760d1bc6a73fd48157724a0c534cce4af4f6 Mon Sep 17 00:00:00 2001 From: yeasy Date: Thu, 23 Jul 2026 17:27:39 -0700 Subject: [PATCH] ci: drop the two Dependabot auto-merge steps that could never work MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Neither step did what its name said, and together they meant no Dependabot PR was ever auto-merged — the job died before reaching the merge step. 1. "Confirm required checks are configured" failed OPEN. It read branch protection, which GITHUB_TOKEN cannot do (administration scope is not even a valid permissions key), so gh api returned 403 JSON into REQUIRED and `[ "$REQUIRED" -eq 0 ]` died with "integer expression expected". A failing test inside an `if` condition is exempt from set -e, so the guard evaluated false and let execution continue. A guard whose whole purpose is refusing an unsafe merge silently passed whenever it could not check. 2. "Approve low-risk Dependabot PR" can never succeed: GitHub Actions is not permitted to approve pull requests. It is also unnecessary — these repos do not require reviews. The real gate is now branch protection, which as of today requires BOTH check-commit-identity and CI on every repo, and gh pr merge --auto cannot complete until they pass. That is stronger than the removed probe, which only checked that some required check existed. This makes the 13 repos match oc_guide, which already had exactly this shape and was the only one whose auto-merge was not broken. prompt_engineering_guide asserted the old step ORDER; its test now asserts the invariants that still hold — no self-approve attempt, and auto-merge gated on the low-risk update-type allowlist. --- .github/workflows/dependabot-automerge.yml | 22 ---------------------- 1 file changed, 22 deletions(-) diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml index fddb46e..9476a09 100644 --- a/.github/workflows/dependabot-automerge.yml +++ b/.github/workflows/dependabot-automerge.yml @@ -19,28 +19,6 @@ jobs: with: github-token: "${{ secrets.GITHUB_TOKEN }}" - - name: Confirm required checks are configured - if: > - steps.metadata.outputs.package-ecosystem == 'github_actions' && - contains(fromJSON('["version-update:semver-patch","version-update:semver-minor"]'), steps.metadata.outputs.update-type) - run: | - REQUIRED=$(gh api "repos/${GITHUB_REPOSITORY}/branches/${{ github.event.pull_request.base.ref }}/protection/required_status_checks" --jq '((.contexts // []) | length) + ((.checks // []) | length)' 2>/dev/null || echo 0) - if [ "$REQUIRED" -eq 0 ]; then - echo "No required status checks configured on the base branch; refusing Dependabot auto-merge." - exit 1 - fi - env: - GH_TOKEN: ${{secrets.GITHUB_TOKEN}} - - - name: Approve low-risk Dependabot PR - if: > - steps.metadata.outputs.package-ecosystem == 'github_actions' && - contains(fromJSON('["version-update:semver-patch","version-update:semver-minor"]'), steps.metadata.outputs.update-type) - run: gh pr review --approve "$PR_URL" - env: - PR_URL: ${{github.event.pull_request.html_url}} - GH_TOKEN: ${{secrets.GITHUB_TOKEN}} - - name: Enable auto-merge for low-risk Dependabot PRs if: > steps.metadata.outputs.package-ecosystem == 'github_actions' &&