fix(ci): guard dependabot auto-merge on green CI

Root cause of recurring breaking bumps: dependabot-auto-merge ran
gh pr merge --auto with no CI gate and the repo has no branch protection,
so PRs merged the moment checks finished — including FAILED ones
(eslint@10, tsparticles@4, typescript@7 all landed repeatedly).

Add a github-script step: list check-runs for the PR head, fail unless
all checks completed AND none failed. Breaking bumps now block instead
of silently landing.
This commit is contained in:
asepharyana
2026-09-20 22:08:39 +07:00
parent fb91f3df90
commit 0810ff1373
+27
View File
@@ -4,12 +4,39 @@ on: pull_request
permissions: permissions:
contents: write contents: write
pull-requests: write pull-requests: write
checks: read
jobs: jobs:
auto-merge: auto-merge:
runs-on: ubuntu-latest runs-on: ubuntu-latest
# Only for dependabot PRs whose CI is green: the "CI" workflow must have
# completed successfully before auto-merge is enabled. Without this guard,
# gh pr merge --auto merges as soon as checks finish — including failures
# (breaking bumps like eslint@10 / tsparticles@4 / typescript@7 landed
# repeatedly because of that).
if: github.actor == 'dependabot[bot]' if: github.actor == 'dependabot[bot]'
steps: steps:
- name: Wait for CI checks to pass
uses: actions/github-script@v7
with:
script: |
const { data: checks } = await github.rest.checks.listForRef({
owner: context.repo.owner,
repo: context.repo.repo,
ref: context.payload.pull_request.head.sha,
});
const pending = checks.check_runs.filter((c) => c.status !== "completed");
if (pending.length > 0) {
core.setFailed(`CI not finished yet: ${pending.map((c) => c.name).join(", ")}`);
return;
}
const failed = checks.check_runs.filter((c) => c.conclusion === "failure");
if (failed.length > 0) {
core.setFailed(`CI failed: ${failed.map((c) => c.name).join(", ")}`);
return;
}
core.notice(`All ${checks.check_runs.length} checks passed — enabling auto-merge.`);
- name: Enable auto-merge for Dependabot PR - name: Enable auto-merge for Dependabot PR
run: gh pr merge --auto --merge "$PR_URL" run: gh pr merge --auto --merge "$PR_URL"
env: env: