Dependabot auto-merge #402
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Dependabot auto-merge | |
| # Merges a Dependabot PR only once CI has actually reported green. The logic lives in | |
| # ktsu-dev/.github so that changing how Dependabot PRs are gated is one edit rather than | |
| # fifty; see docs/dependabot-auto-merge.md there for why it is shaped this way. | |
| # | |
| # The `workflows:` list below must name every workflow this repository runs on a pull | |
| # request, by the workflow's `name:` field rather than its filename. That list is what | |
| # re-opens the merge question: the gate refuses to merge while any check on the commit is | |
| # still pending, so a workflow missing from it is one whose completion never triggers a | |
| # re-evaluation, and a Dependabot PR that is genuinely green can sit unmerged if that | |
| # workflow happens to finish last. Adding a pull-request workflow to this repository means | |
| # adding its name here. Naming one that does not exist is harmless; it simply never fires. | |
| on: | |
| workflow_run: | |
| workflows: | |
| - ".NET Workflow" | |
| types: [completed] | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| jobs: | |
| merge: | |
| # A failed or cancelled run is not "not yet" — it must never reach the merge step. | |
| if: > | |
| github.event.workflow_run.event == 'pull_request' && | |
| github.event.workflow_run.conclusion == 'success' | |
| uses: ktsu-dev/.github/.github/workflows/dependabot-merge.yml@main | |
| with: | |
| head-sha: ${{ github.event.workflow_run.head_sha }} |