Dependabot auto merge addition in github workflows (#1459)

Dependabot auto-merge feature. Auto-merge triggers for dependabot depencency pull requests that are patches and have a cvss level greater than zero.
This commit is contained in:
skyero-aws 2025-04-01 11:02:17 -07:00 committed by GitHub
parent edd7d9b1e5
commit 133374706c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 53 additions and 35 deletions

View file

@ -1,32 +1,31 @@
version: 2 version: 2
updates: updates:
# branch - master # branch - master
- package-ecosystem: "maven" - package-ecosystem: "maven"
directory: "/" directory: "/"
labels: labels:
- "dependencies" - "dependencies"
- "v3.x" - "v3.x"
target-branch: "master" target-branch: "master"
schedule: schedule:
interval: "weekly" interval: "weekly"
# branch - v2.x # branch - v2.x
- package-ecosystem: "maven" - package-ecosystem: "maven"
directory: "/" directory: "/"
labels: labels:
- "dependencies" - "dependencies"
- "v2.x" - "v2.x"
target-branch: "v2.x" target-branch: "v2.x"
schedule: schedule:
interval: "weekly" interval: "weekly"
# branch - v1.x
- package-ecosystem: "maven"
directory: "/"
labels:
- "dependencies"
- "v1.x"
target-branch: "v1.x"
schedule:
interval: "weekly"
# branch - v1.x
- package-ecosystem: "maven"
directory: "/"
labels:
- "dependencies"
- "v1.x"
target-branch: "v1.x"
schedule:
interval: "weekly"

View file

@ -7,20 +7,25 @@
# documentation. # documentation.
name: Java CI with Maven name: Java CI with Maven
on: on:
push: push:
branches: branches:
- "master" - "master"
- "v2.x"
- "v1.x"
pull_request: pull_request:
branches: branches:
- "master" - "master"
- "v2.x"
- "v1.x"
permissions:
contents: write
pull-requests: write
jobs: jobs:
build: build:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- name: Set up JDK 8 - name: Set up JDK 8
@ -30,11 +35,8 @@ jobs:
distribution: 'corretto' distribution: 'corretto'
- name: Build with Maven - name: Build with Maven
run: mvn -B package --file pom.xml -DskipITs run: mvn -B package --file pom.xml -DskipITs
backwards-compatible-check: backwards-compatible-check:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- name: Set up JDK 8 - name: Set up JDK 8
@ -43,4 +45,21 @@ jobs:
java-version: '8' java-version: '8'
distribution: 'corretto' distribution: 'corretto'
- name: Check backwards compatibility of changes - name: Check backwards compatibility of changes
run: .github/scripts/backwards_compatibility_check.sh run: .github/scripts/backwards_compatibility_check.sh
auto-merge:
needs: [build]
runs-on: ubuntu-latest
if: github.event.pull_request.user.login == 'dependabot[bot]'
steps:
- name: Dependabot metadata
id: metadata
uses: dependabot/fetch-metadata@v2
with:
alert-lookup: true
github-token: "${{ secrets.GITHUB_TOKEN }}"
- name: Enable auto-merge for Dependabot PRs
if: steps.metadata.outputs.update-type == 'version-update:semver-patch' && steps.metadata.outputs.cvss > 0
run: gh pr merge --auto --merge "$PR_URL"
env:
PR_URL: ${{github.event.pull_request.html_url}}
GH_TOKEN: ${{secrets.GITHUB_TOKEN}}