The workflow read the old and new versions from the PR title. A group
PR title has no versions ('bump the npm_and_yarn group ... with 9
updates'), so the job failed (webdriverio#1295). fetch-metadata already gives the
highest semver change of the PR as update-type: npm updates of type
minor or patch are merged automatically; major, unknown (for example
indirect updates, where update-type is null) and GitHub Actions updates
wait for a person, as before.
This also removes ${{ github.event.pull_request.title }} from a run:
script (script injection).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Summary
The Dependabot auto-merge job (
update.yml) read the old and new versions from the PR title ("from x.y.z to a.b.c"). A group PR title has no versions ("bump the npm_and_yarn group across 1 directory with 9 updates"), so the job failed with "Version numbers not found in PR title" and showed a red check (#1295).dependabot/fetch-metadataalready gives the highest semver change of the PR asupdate-type, also for groups. The workflow now uses it.Changes
update-typeversion-update:semver-minororversion-update:semver-patch.update-type: null, like #1295)${{ github.event.pull_request.title }}from arun:script, which was a script-injection risk.Test
outputs.update-type: nullandoutputs.package-ecosystem: npm_and_yarnfor a group of indirect updates, so with the new condition that PR would wait for a person instead of failing.🤖 Generated with Claude Code