Skip to content

ci: decide Dependabot auto-merge with fetch-metadata's update-type - #1296

Merged
plum117 merged 1 commit into
webdriverio:mainfrom
plum117:ci/automerge-group-prs
Oct 9, 2026
Merged

plum117 merged 1 commit into
webdriverio:mainfrom
plum117:ci/automerge-group-prs

Conversation

@plum117

@plum117 plum117 commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Summary

The Dependabot auto-merge job (update.yml) read the old and new versions from the PR title ("from x.y.z to a.b.c"). A group PR title has no versions ("bump the npm_and_yarn group across 1 directory with 9 updates"), so the job failed with "Version numbers not found in PR title" and showed a red check (#1295).

dependabot/fetch-metadata already gives the highest semver change of the PR as update-type, also for groups. The workflow now uses it.

Changes

  • Removed the 3 steps that read the title, extracted the versions and compared the majors.
  • The wait and auto-merge steps run only for npm updates with update-type version-update:semver-minor or version-update:semver-patch.
  • Behavior:
Update Before After
Single npm minor/patch auto-merge auto-merge
Single npm major waits for a person waits for a person
Group of direct updates job failed auto-merge if the highest change is minor/patch, else waits
Group of indirect updates (update-type: null, like #1295) job failed waits for a person (job passes)
GitHub Actions updates waits for a person waits for a person
  • Also removes ${{ github.event.pull_request.title }} from a run: script, which was a script-injection risk.

Test

🤖 Generated with Claude Code

The workflow read the old and new versions from the PR title. A group
PR title has no versions ('bump the npm_and_yarn group ... with 9
updates'), so the job failed (webdriverio#1295). fetch-metadata already gives the
highest semver change of the PR as update-type: npm updates of type
minor or patch are merged automatically; major, unknown (for example
indirect updates, where update-type is null) and GitHub Actions updates
wait for a person, as before.

This also removes ${{ github.event.pull_request.title }} from a run:
script (script injection).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@changeset-bot

changeset-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: dfebd0d

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@plum117
plum117 marked this pull request as ready for review October 9, 2026 02:20
@greptile-apps

greptile-apps Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High impact] The PR appears safe to merge; no actionable issues were found.

Summary

Replaces PR-title parsing with fetch-metadata outputs to decide which Dependabot updates can merge automatically.

  • Dependabot updates use their reported change type to decide auto-merge.

Reviews (1) · Last reviewed commit: "ci: decide Dependabot auto-merge with fe..." · Reviewed by Greptile

@plum117
plum117 merged commit 3192690 into webdriverio:main Oct 9, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants