diff --git a/.github/workflows/update.yml b/.github/workflows/update.yml index 77d5891b7..f55c1a613 100644 --- a/.github/workflows/update.yml +++ b/.github/workflows/update.yml @@ -23,48 +23,12 @@ jobs: with: github-token: ${{ secrets.GITHUB_TOKEN }} - # Get PR title to extract the version change information - # The title of the Dependabot PR contains the old and new version numbers. - - name: Get PR Title - id: pr-title - run: echo "PR_TITLE=${{ github.event.pull_request.title }}" >> $GITHUB_ENV - - # Extract old and new version numbers from the PR title - # We use regex to capture the old and new version numbers from the PR title format - # The format usually looks like "Bump package-name from x.y.z to a.b.c" - # If there is no version number in the PR title, the workflow will exit with an error so we manually need to verify the version numbers. - - name: Extract old and new versions - id: extract-versions - run: | - if [[ "${{ env.PR_TITLE }}" =~ from[[:space:]]?([0-9]+\.[0-9]+\.[0-9]+)[[:space:]]?to[[:space:]]?([0-9]+\.[0-9]+\.[0-9]+) ]]; then - echo "OLD_VERSION=${BASH_REMATCH[1]}" >> $GITHUB_ENV - echo "NEW_VERSION=${BASH_REMATCH[2]}" >> $GITHUB_ENV - else - echo "Version numbers not found in PR title." - exit 1 - fi - - # Check the type of version bump (major, minor, or patch) - # We compare the major version numbers between old and new versions. - # If the new major version is greater than the old one, it's a major bump. - - name: Check version bump type - id: check-bump-type - run: | - IFS='.' read -r -a old_version_parts <<< "${{ env.OLD_VERSION }}" - IFS='.' read -r -a new_version_parts <<< "${{ env.NEW_VERSION }}" - - if [[ "${new_version_parts[0]}" -gt "${old_version_parts[0]}" ]]; then - echo "MAJOR_BUMP=true" >> $GITHUB_ENV - else - echo "MAJOR_BUMP=false" >> $GITHUB_ENV - fi - # Wait for all CI checks on the PR to pass - # Don't merge updates to GitHub Actions versions automatically. - # We also prevent auto-merging if a major version bump is detected. - # (Some repos may wish to limit by version range (major/minor/patch), or scope (dep vs dev-dep), too.) + # Only npm updates of type minor or patch are merged automatically. `update-type` is the highest semver change + # of the PR, also for a group of updates (whose title has no versions). Major, unknown and GitHub Actions + # updates wait for a person. - name: Wait for PR CI - if: contains(steps.metadata.outputs.package-ecosystem, 'npm') && env.MAJOR_BUMP == 'false' + if: contains(steps.metadata.outputs.package-ecosystem, 'npm') && contains(fromJSON('["version-update:semver-minor","version-update:semver-patch"]'), steps.metadata.outputs.update-type) uses: lewagon/wait-on-check-action@3603e826ee561ea102b58accb5ea55a1a7482343 # v1.4.1 with: ref: ${{ github.event.pull_request.head.sha }} @@ -76,13 +40,11 @@ jobs: # `main` is analyzed after the merge. Canceled or failed checks (also a CodeQL finding) still block it. allowed-conclusions: success,skipped,neutral - # Auto-merge Dependabot PRs - # Don't merge updates to GitHub Actions versions automatically. - # Ensure that only non-major version bumps (minor or patch) are merged automatically. + # Auto-merge Dependabot PRs (same condition as above) # The "auto" flag will only merge once all of the target branch's required checks # are met. Configure those in the "branch protection" settings for each repo. - name: Auto-merge dependabot PRs - if: contains(steps.metadata.outputs.package-ecosystem, 'npm') && env.MAJOR_BUMP == 'false' + if: contains(steps.metadata.outputs.package-ecosystem, 'npm') && contains(fromJSON('["version-update:semver-minor","version-update:semver-patch"]'), steps.metadata.outputs.update-type) env: PR_URL: ${{ github.event.pull_request.html_url }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}