Skip to content

Commit b570d4e

Browse files
Jlougedo-TFclaude
andcommitted
ci(NOJIRA-1234): Withhold approval from risky bot PRs
Assess risk first, then approve only when the diff looks routine. A risky PR now gets no approval at all, so it cannot satisfy the required-review count and a human has to sign it off - the label alone was advisory, since a bot approval already met the review requirement. Also close the stale-arming gap: a PR can open looking routine (approved, auto-merge armed) and then be force-pushed into something risky. On the risky path the workflow now calls 'gh pr merge --disable-auto' and dismisses its own earlier approval before labelling and commenting. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
1 parent 26ede12 commit b570d4e

1 file changed

Lines changed: 24 additions & 9 deletions

File tree

‎.github/workflows/dependabot-automerge.yml‎

Lines changed: 24 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -15,15 +15,10 @@ jobs:
1515
if: contains(fromJSON('["dependabot[bot]", "aikido-autofix[bot]"]'), github.actor)
1616

1717
steps:
18-
- name: Approve bot PR
19-
run: gh pr review --approve "$PR_URL"
20-
env:
21-
PR_URL: ${{ github.event.pull_request.html_url }}
22-
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
23-
2418
# A green CI run does not prove a transitive bump is safe: the repo's own
2519
# tests never exercise how the intermediate package uses the changed API.
26-
# Anything matching below is left for a human instead of auto-merging.
20+
# Anything matching below is neither approved nor auto-merged, so it cannot
21+
# satisfy the required-review count and a human has to sign it off.
2722
- name: Assess dependency risk
2823
id: risk
2924
run: |
@@ -77,20 +72,40 @@ jobs:
7772
PR_TITLE: ${{ github.event.pull_request.title }}
7873
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
7974

75+
- name: Approve bot PR
76+
if: steps.risk.outputs.risky == 'false'
77+
run: gh pr review --approve "$PR_URL"
78+
env:
79+
PR_URL: ${{ github.event.pull_request.html_url }}
80+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
81+
8082
- name: Enable auto-merge for bot PR
8183
if: steps.risk.outputs.risky == 'false'
8284
run: gh pr merge --auto --squash "$PR_URL"
8385
env:
8486
PR_URL: ${{ github.event.pull_request.html_url }}
8587
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
8688

87-
- name: Flag risky bot PR for human review
89+
- name: Hold risky bot PR for human review
8890
if: steps.risk.outputs.risky == 'true'
8991
run: |
92+
# An earlier run may have approved and armed this PR while it still
93+
# looked routine, so undo both before flagging it.
94+
gh pr merge --disable-auto "$PR_URL" || true
95+
96+
gh api "repos/$REPO/pulls/$PR_NUMBER/reviews" \
97+
--jq '.[] | select(.state == "APPROVED" and .user.login == "github-actions[bot]") | .id' \
98+
| while read -r id; do
99+
gh api -X PUT "repos/$REPO/pulls/$PR_NUMBER/reviews/$id/dismissals" \
100+
-f message="Withdrawn: $REASON" >/dev/null || true
101+
done
102+
90103
gh pr edit "$PR_URL" --add-label needs-human
91104
gh pr comment "$PR_URL" --body \
92-
"Not auto-merged: **$REASON**. A green CI run does not prove a transitive dependency bump is safe, so this one needs a human look."
105+
"Held for human review: **$REASON**. A green CI run does not prove a transitive dependency bump is safe, so this PR was deliberately **not** approved and auto-merge is off. It needs a human to review and merge it."
93106
env:
94107
PR_URL: ${{ github.event.pull_request.html_url }}
108+
REPO: ${{ github.repository }}
109+
PR_NUMBER: ${{ github.event.pull_request.number }}
95110
REASON: ${{ steps.risk.outputs.reason }}
96111
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

0 commit comments

Comments
 (0)