Skip to content

ci(NOJIRA-1234): Extend bot automerge to smartling and aikido - #761

Merged
Jlougedo-TF merged 10 commits into
mainfrom
NOJIRA-1234/bot-pr-automerge
Oct 8, 2026
Merged

Jlougedo-TF merged 10 commits into
mainfrom
NOJIRA-1234/bot-pr-automerge

Conversation

@Jlougedo-TF

Copy link
Copy Markdown
Contributor

Gate on the PR author login instead of a single actor, so translation PRs from smartling-github-connector[bot] and security fixes from aikido-autofix[bot] are auto-approved and auto-merged alongside dependabot.

Titles are not a reliable signal for these bots, so the allowlist keys off github.actor only.

Overview

Jira ticket: https://typeform.atlassian.net/browse/<TICKET_ID>

Changes

Testing

Docs

  • Yes! ✋ I have updated the documentation.

For contributions to the Typeform/.github repo

Note: Please do not use this repository for new internal shared workflows and actions. Use https://github.com/Typeform/.github-private instead!

Please check that your contribution applies to one of these cases below. If this is not the case, please contribute to https://github.com/Typeform/.github-private instead.

  • This PR only changes an existing workflow.
  • This PR adds a new workflow that is needed in a public Typeform repository.

Gate on the PR author login instead of a single actor, so translation PRs
from smartling-github-connector[bot] and security fixes from
aikido-autofix[bot] are auto-approved and auto-merged alongside dependabot.

Titles are not a reliable signal for these bots, so the allowlist keys off
github.actor only.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@Jlougedo-TF Jlougedo-TF self-assigned this Sep 9, 2026
@Jlougedo-TF
Jlougedo-TF requested a review from a team as a code owner September 9, 2026 13:28
@pr-auditor

pr-auditor Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

✅ Security Analysis Results

No security issues found. 1 files reviewed.

Resolved Issues (1)
Status Category File Details
Fixed business_logic .github/workflows/dependabot-automerge.yml The diff retains the sixth heuristic ('Assess dependency risk' check #6) that flags any aikido-autofix[bot] PR touching files outside the dependency manifest/lockfile allowlist as risky, routing it to the human-review hold path (dismissing prior approval, disabling auto-merge, adding needs-human label) instead of silently auto-merging. Confirmed consistent with developer's backtest of 72 historical Aikido PRs with 0 false positives; no regressions introduced in this round.

@pr-auditor rescan to re-run · Powered by Claude Sonnet 5.5 · Docs · #security-engineering-team

Jlougedo-TF and others added 3 commits September 9, 2026 15:35
This repo has no Smartling-managed content: the smartling-github-connector[bot]
has never opened a PR here and there is no Smartling config. Narrow the
allowlist to the bots that actually raise PRs in this repo.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
A green CI run does not prove a transitive dependency bump is safe: the
repo's own tests never exercise how the intermediate package uses the changed
API. Approve as before, but only arm auto-merge when the diff looks routine.

Held back for a human when any of these match:
  - the bot's title declares a major version upgrade
  - a JS manifest touches resolutions/overrides (a forced transitive pin)
  - go.mod gains a +incompatible major bump
  - more than 6 manifest dependency lines change at once
  - the lockfile rewrite exceeds 600 lines

Validated against 13 real bot PRs: correctly holds xfiles#543 (docker v24->v25
+incompatible), blocks#3039 (major axios), renderer#1481 and mail-composer#400
(forced resolutions), and correctly passes the single direct minor bumps such
as embed#760, pages#620 and purgatory#314.

Also drops the checkout and 'apt-get install gh' steps: nothing read the working
tree (gh is API-only) and gh ships on ubuntu-latest. All repos now hold a
byte-identical file apart from the allowlist line.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assess risk first, then approve only when the diff looks routine. A risky PR
now gets no approval at all, so it cannot satisfy the required-review count and
a human has to sign it off - the label alone was advisory, since a bot approval
already met the review requirement.

Also close the stale-arming gap: a PR can open looking routine (approved,
auto-merge armed) and then be force-pushed into something risky. On the risky
path the workflow now calls 'gh pr merge --disable-auto' and dismisses its own
earlier approval before labelling and commenting.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@Jlougedo-TF

Copy link
Copy Markdown
Contributor Author

Addressed the aikido finding: for aikido-autofix[bot] the workflow now holds (no approval, no auto-merge, needs-human label) any PR touching a file that is not a dependency manifest or lockfile (package.json, yarn.lock, package-lock.json, pnpm-lock.yaml, go.mod, go.sum, requirements*.txt/.in). Backtested on 72 historical Aikido PRs: 0 false positives.

@pr-auditor rescan

mfrederic
mfrederic previously approved these changes Oct 7, 2026
@github-actions github-actions Bot added the size/m label Oct 8, 2026
@Jlougedo-TF
Jlougedo-TF enabled auto-merge (squash) October 8, 2026 15:04
@jenkins-tf

Copy link
Copy Markdown
Collaborator

[BOT] Preview available with hash 41264c36d01d93a251910efa2c7f81493652e9fe here.

@Jlougedo-TF
Jlougedo-TF merged commit 62d255f into main Oct 8, 2026
9 checks passed
@Jlougedo-TF
Jlougedo-TF deleted the NOJIRA-1234/bot-pr-automerge branch October 8, 2026 15:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants