Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 56 additions & 0 deletions .github/workflows/dependabot-maintenance.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
# =============================================================================
# Dependabot Maintenance - LIB-Shared-NET
# =============================================================================
# Merges Dependabot PRs once the PR CI that builds and tests them has passed,
# using the reusable workflow from bauer-group/automation-templates
# (docs/workflows/docker-maintenance.md).
#
# Trigger scope: no `paths:` filter, so every Dependabot PR - whatever its
# ecosystem - gets an explicit decision (merged, or left open with an
# annotation and a job summary) instead of silently staying open.
# - NuGet: Dependabot changes Directory.Packages.props (central package
# management) or a VersionOverride in a csproj under src/. Both are in the
# pull_request paths of dotnet-release.yml, whose PR run builds the whole
# solution and runs the tests (Windows and Linux/Avalonia) and packs the
# libraries - that run must pass.
# - GitHub Actions updates and any other PR that changes .github/ are never
# merged automatically (guard of the reusable workflow) - merge by hand.
#
# Release: the NuGet commit prefix is "deps(dotnet)", which the
# semantic-release config maps to a PATCH release. The merge itself is made
# with GITHUB_TOKEN and starts no push workflow, so the release follows with
# the next push to main that is not made by that token, or a manual run of
# dotnet-release.yml.
# =============================================================================

name: 馃 Dependabot Maintenance

on:
pull_request:
types: [opened, synchronize, reopened, ready_for_review]

# The reusable workflow declares no permissions of its own - the token has
# exactly these. The three read scopes are needed in private repositories and
# keep the workflow working should this repository ever be made private.
permissions:
contents: write # merge
pull-requests: write # approve, read the PR
checks: read # check runs and suites
statuses: read # commit statuses
actions: read # workflow runs

jobs:
maintenance:
name: Auto-merge Dependabot PRs
uses: bauer-group/automation-templates/.github/workflows/docker-maintenance-dependabot.yml@main
with:
# The PR CI that builds and tests the update; a PR it did not run for
# stays open as "not tested".
required-workflows: .github/workflows/dotnet-release.yml
merge-method: 'squash'
auto-approve: true
# Patch updates only. Below 1.0.0 a minor update (0.3.1 -> 0.4.0) and a
# 0.0.z patch update count as major and stay open for review; in a
# grouped update the strictest dependency decides.
merge-update-types: 'patch'
secrets: inherit
Loading