Repository navigation
ci(NOJIRA-1234): Extend bot automerge to smartling and aikido - #761
Merged
Merged
Conversation
Gate on the PR author login instead of a single actor, so translation PRs from smartling-github-connector[bot] and security fixes from aikido-autofix[bot] are auto-approved and auto-merged alongside dependabot. Titles are not a reliable signal for these bots, so the allowlist keys off github.actor only. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
✅ Security Analysis ResultsNo security issues found. 1 files reviewed. Resolved Issues (1)
|
This repo has no Smartling-managed content: the smartling-github-connector[bot] has never opened a PR here and there is no Smartling config. Narrow the allowlist to the bots that actually raise PRs in this repo. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
A green CI run does not prove a transitive dependency bump is safe: the repo's own tests never exercise how the intermediate package uses the changed API. Approve as before, but only arm auto-merge when the diff looks routine. Held back for a human when any of these match: - the bot's title declares a major version upgrade - a JS manifest touches resolutions/overrides (a forced transitive pin) - go.mod gains a +incompatible major bump - more than 6 manifest dependency lines change at once - the lockfile rewrite exceeds 600 lines Validated against 13 real bot PRs: correctly holds xfiles#543 (docker v24->v25 +incompatible), blocks#3039 (major axios), renderer#1481 and mail-composer#400 (forced resolutions), and correctly passes the single direct minor bumps such as embed#760, pages#620 and purgatory#314. Also drops the checkout and 'apt-get install gh' steps: nothing read the working tree (gh is API-only) and gh ships on ubuntu-latest. All repos now hold a byte-identical file apart from the allowlist line. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assess risk first, then approve only when the diff looks routine. A risky PR now gets no approval at all, so it cannot satisfy the required-review count and a human has to sign it off - the label alone was advisory, since a bot approval already met the review requirement. Also close the stale-arming gap: a PR can open looking routine (approved, auto-merge armed) and then be force-pushed into something risky. On the risky path the workflow now calls 'gh pr merge --disable-auto' and dismisses its own earlier approval before labelling and commenting. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Contributor
Author
|
Addressed the aikido finding: for aikido-autofix[bot] the workflow now holds (no approval, no auto-merge, needs-human label) any PR touching a file that is not a dependency manifest or lockfile (package.json, yarn.lock, package-lock.json, pnpm-lock.yaml, go.mod, go.sum, requirements*.txt/.in). Backtested on 72 historical Aikido PRs: 0 false positives. @pr-auditor rescan |
mfrederic
previously approved these changes
Oct 7, 2026
mfrederic
approved these changes
Oct 7, 2026
mfrederic
approved these changes
Oct 7, 2026
Jlougedo-TF
enabled auto-merge (squash)
October 8, 2026 15:04
Collaborator
|
[BOT] Preview available with hash |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Gate on the PR author login instead of a single actor, so translation PRs from smartling-github-connector[bot] and security fixes from aikido-autofix[bot] are auto-approved and auto-merged alongside dependabot.
Titles are not a reliable signal for these bots, so the allowlist keys off github.actor only.
Overview
Jira ticket: https://typeform.atlassian.net/browse/<TICKET_ID>
Changes
Testing
Docs
For contributions to the
Typeform/.githubrepoNote: Please do not use this repository for new internal shared workflows and actions. Use https://github.com/Typeform/.github-private instead!
Please check that your contribution applies to one of these cases below. If this is not the case, please contribute to https://github.com/Typeform/.github-private instead.