Files
nextjs-template/.github/dependabot-auto-merge.yml
T
asepharyana 02b4437eb3 fix: stop dependabot auto-merge from landing breaking majors
Root causes (this round):
- dependabot.yml had been overwritten to a minimal version with NO
  ignore rules -> major bumps allowed (typescript 7, eslint 10, tsparticles 4)
- main branch had NO branch protection -> 'gh pr merge --auto' merged
  even with failing CI
- auto-merge workflow had no check-run verification step

Fixes:
- Branch protection on main: required status check 'lint + typecheck +
  test + build' (strict) so auto-merge cannot land failing changes
- dependabot-auto-merge.yml: verify CI check-run conclusion == success
  (actions/github-script poll with timeout) before enabling auto-merge
- dependabot.yml: restore ignore rules for eslint/typescript/@tsparticles
  majors + eslint-config-next + eslint-plugin-react
- Rollback toolchain to known-good exact pins:
  typescript 6.0.3, eslint 9.39.5, @tsparticles/{react,engine,slim} 3.x
  (exact versions, no ranges dependabot can widen)
- Close dependabot PR #19 (tsparticles 4.4.0)
2026-09-21 11:03:34 +07:00

55 lines
1.9 KiB
YAML

name: Dependabot Auto-Merge
on: pull_request
permissions:
contents: write
pull-requests: write
checks: read
jobs:
auto-merge:
runs-on: ubuntu-latest
if: github.actor == 'dependabot[bot]'
steps:
- name: Verify CI check-runs before enabling auto-merge
uses: actions/github-script@v7
with:
script: |
const owner = context.repo.owner;
const repo = context.repo.repo;
const sha = context.payload.pull_request.head.sha;
// Wait for in-progress runs (with timeout), then collect conclusions
const requiredContext = "lint + typecheck + test + build";
let conclusion = null;
for (let attempt = 0; attempt < 60; attempt++) {
const { data: checks } = await github.rest.checks.listForRef({
owner, repo, ref: sha,
});
const match = checks.check_runs.find(
(r) => r.name === requiredContext || r.output?.title === requiredContext
);
if (match && match.status === "completed") {
conclusion = match.conclusion;
break;
}
await new Promise((r) => setTimeout(r, 10000));
}
if (!conclusion) {
core.setFailed(`Required check "${requiredContext}" never completed within timeout.`);
return;
}
if (conclusion !== "success") {
core.setFailed(`Required check "${requiredContext}" concluded ${conclusion}. NOT merging.`);
return;
}
core.info(`Check "${requiredContext}" passed — safe to enable auto-merge.`);
- name: Enable auto-merge for Dependabot PR
if: success()
run: gh pr merge --auto --merge "$PR_URL"
env:
PR_URL: ${{ github.event.pull_request.html_url }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}