Skip to content

merge queue: embarking main (e2875ab) and [#99 + #100] together #189

merge queue: embarking main (e2875ab) and [#99 + #100] together

merge queue: embarking main (e2875ab) and [#99 + #100] together #189

---
name: Dependabot auto-approve
on:
pull_request:
permissions:
contents: write
pull-requests: write
jobs:
dependabot-auto-approve:
runs-on: ubuntu-latest
if: ${{ github.event.pull_request.user.login == 'dependabot[bot]' }}
steps:
- name: Dependabot metadata
id: dependabot-metadata
uses: dependabot/fetch-metadata@v1
with:
github-token: "${{ secrets.GITHUB_TOKEN }}"
- name: Approve patch and minor updates
if: ${{steps.dependabot-metadata.outputs.update-type == 'version-update:semver-patch' || steps.dependabot-metadata.outputs.update-type == 'version-update:semver-minor'}}
run: gh pr review "${PR_URL}" --approve --body "I **approve** this pull request because it includes a **patch or minor update**."
env:
PR_URL: ${{github.event.pull_request.html_url}}
GITHUB_TOKEN: ${{secrets.GITHUB_TOKEN}}
- name: Approve major updates of development dependencies
if: ${{steps.dependabot-metadata.outputs.update-type == 'version-update:semver-major' && steps.dependabot-metadata.outputs.dependency-type == 'direct:development'}}
run: gh pr review "${PR_URL}" --approve -b "I **approve** this pull request because it includes a **major update of a dependency used only in development**."
env:
PR_URL: ${{github.event.pull_request.html_url}}
GITHUB_TOKEN: ${{secrets.GITHUB_TOKEN}}
- name: Comment on major updates of non-development dependencies
if: ${{steps.dependabot-metadata.outputs.update-type == 'version-update:semver-major' && steps.dependabot-metadata.outputs.dependency-type == 'direct:production'}}
run: |
gh pr comment "${PR_URL}" --body "I **do not approve** this PR because it includes a **major update of a dependency used in production**."
gh pr edit "${PR_URL}" --add-label "help wanted"
env:
PR_URL: ${{github.event.pull_request.html_url}}
GITHUB_TOKEN: ${{secrets.GITHUB_TOKEN}}