Repository navigation
ci(dependabot): added Dependabot auto-merge caller workflow - #168
Merged
Merged
Conversation
NuGet updates from Dependabot piled up as open PRs (9 open right now) although dotnet-release.yml already builds and tests them on the PR. The repository had no caller of the shared docker-maintenance-dependabot workflow, so nothing ever decided on them. * New .github/workflows/dependabot-maintenance.yml calls the reusable workflow from bauer-group/automation-templates@main * No paths filter: every Dependabot PR, whatever its ecosystem, reaches the workflow and gets an explicit decision with an annotation instead of silently staying open * required-workflows = dotnet-release.yml: its pull_request run builds the whole solution, runs the tests on Windows and the Avalonia tests on Linux and packs the libraries. Its PR paths already cover every file the NuGet updater changes here (Directory.Packages.props, VersionOverride in src/**/*.csproj), so it needed no change * Patch updates only, squash merge, auto-approve; GitHub Actions updates and other .github/ changes stay manual (module guard) * Permissions: contents/pull-requests write for merge and approve, checks/statuses/actions read for the CI state The NuGet prefix deps(dotnet) maps to a PATCH release in the semantic-release config, so every merged update cuts a NuGet release with the next push to main that is not made by GITHUB_TOKEN (the merge itself starts no push workflow).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Dependabot opens weekly NuGet update PRs here (9 are open right now), and
dotnet-release.ymlalready builds and tests each of them on the PR. But the repository had no caller of the shareddocker-maintenance-dependabot.ymlworkflow, so nothing decided on them: green PRs waited for a manual merge, and nothing marked which ones were safe to merge.What
New
.github/workflows/dependabot-maintenance.yml, which callsbauer-group/automation-templates/.github/workflows/docker-maintenance-dependabot.yml@main(based on theown-build-and-test-workflow.ymlexample):paths:filter. Every Dependabot PR reaches the module, whatever its ecosystem, and gets an explicit decision: it is either merged or left open with an annotation and a job summary.types: [opened, synchronize, reopened, ready_for_review].required-workflows: .github/workflows/dotnet-release.yml. Itspull_requestrun buildsBAUERGROUP.Shared.slnxand runs the tests onwindows-latest, runs the Avalonia headless tests onubuntu-latest, and packs the libraries (📋 Validate Package (PR)). That run must concludesuccess.dotnet-release.ymlis unchanged. Its PRpaths:already cover every file the NuGet updater changes in this repository. The repository uses central package management, so Dependabot writesDirectory.Packages.props, or aVersionOverrideinsrc/**/*.csproj. Recent Dependabot PRs (deps(dotnet): Bump Avalonia, Avalonia.Headless.XUnit and Avalonia.Themes.Fluent #156, deps(dotnet): Bump coverlet.collector and Moq #164, deps(dotnet): Bump Sentry and Sentry.NLog #166) only touchedDirectory.Packages.propsand all of them started the release workflow. There is nopackages.lock.json,global.jsonordotnet-tools.json, and Dependabot never writesnuget.config.merge-update-types: patch,merge-method: squash,auto-approve: true,secrets: inherit.contents: write,pull-requests: write,checks: read,statuses: read,actions: read.Compatibility
dotnet-release.ymlbuilt and tested successfully is merged automatically. Minor and major updates stay open for review. Under the 0.x rule a 0.y.z minor or a 0.0.z patch counts as major, and in a grouped update the strictest dependency decides. PRs with failing CI, such as deps(dotnet): Bump CefSharp.Wpf.NETCore from 152.0.60 to 152.0.100 #160 and deps(dotnet): Bump Microsoft.Web.WebView2 from 1.0.4191.47 to 1.0.4258.31 #163 today, stay open with a notice..github/, are never merged automatically (the module's own guard). They get a notice and stay open for a manual merge.deps(dotnet), and.github/config/release/semantic-release.jsonmapsdepsto a PATCH release. Every auto-merged update therefore leads to a new NuGet release. It is cut with the next push tomainthat is not made byGITHUB_TOKEN, or with a manual run ofdotnet-release.yml, because the merge itself starts no push workflow. The prefix is left unchanged on purpose..github/. The release workflow's push trigger ignores.github/**, so merging this PR cuts no release.Test
workflow_callinterface onautomation-templates@main.