Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
50 changes: 6 additions & 44 deletions .github/workflows/update.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,48 +23,12 @@ jobs:
with:
github-token: ${{ secrets.GITHUB_TOKEN }}

# Get PR title to extract the version change information
# The title of the Dependabot PR contains the old and new version numbers.
- name: Get PR Title
id: pr-title
run: echo "PR_TITLE=${{ github.event.pull_request.title }}" >> $GITHUB_ENV

# Extract old and new version numbers from the PR title
# We use regex to capture the old and new version numbers from the PR title format
# The format usually looks like "Bump package-name from x.y.z to a.b.c"
# If there is no version number in the PR title, the workflow will exit with an error so we manually need to verify the version numbers.
- name: Extract old and new versions
id: extract-versions
run: |
if [[ "${{ env.PR_TITLE }}" =~ from[[:space:]]?([0-9]+\.[0-9]+\.[0-9]+)[[:space:]]?to[[:space:]]?([0-9]+\.[0-9]+\.[0-9]+) ]]; then
echo "OLD_VERSION=${BASH_REMATCH[1]}" >> $GITHUB_ENV
echo "NEW_VERSION=${BASH_REMATCH[2]}" >> $GITHUB_ENV
else
echo "Version numbers not found in PR title."
exit 1
fi

# Check the type of version bump (major, minor, or patch)
# We compare the major version numbers between old and new versions.
# If the new major version is greater than the old one, it's a major bump.
- name: Check version bump type
id: check-bump-type
run: |
IFS='.' read -r -a old_version_parts <<< "${{ env.OLD_VERSION }}"
IFS='.' read -r -a new_version_parts <<< "${{ env.NEW_VERSION }}"

if [[ "${new_version_parts[0]}" -gt "${old_version_parts[0]}" ]]; then
echo "MAJOR_BUMP=true" >> $GITHUB_ENV
else
echo "MAJOR_BUMP=false" >> $GITHUB_ENV
fi

# Wait for all CI checks on the PR to pass
# Don't merge updates to GitHub Actions versions automatically.
# We also prevent auto-merging if a major version bump is detected.
# (Some repos may wish to limit by version range (major/minor/patch), or scope (dep vs dev-dep), too.)
# Only npm updates of type minor or patch are merged automatically. `update-type` is the highest semver change
# of the PR, also for a group of updates (whose title has no versions). Major, unknown and GitHub Actions
# updates wait for a person.
- name: Wait for PR CI
if: contains(steps.metadata.outputs.package-ecosystem, 'npm') && env.MAJOR_BUMP == 'false'
if: contains(steps.metadata.outputs.package-ecosystem, 'npm') && contains(fromJSON('["version-update:semver-minor","version-update:semver-patch"]'), steps.metadata.outputs.update-type)
uses: lewagon/wait-on-check-action@3603e826ee561ea102b58accb5ea55a1a7482343 # v1.4.1
with:
ref: ${{ github.event.pull_request.head.sha }}
Expand All @@ -76,13 +40,11 @@ jobs:
# `main` is analyzed after the merge. Canceled or failed checks (also a CodeQL finding) still block it.
allowed-conclusions: success,skipped,neutral

# Auto-merge Dependabot PRs
# Don't merge updates to GitHub Actions versions automatically.
# Ensure that only non-major version bumps (minor or patch) are merged automatically.
# Auto-merge Dependabot PRs (same condition as above)
# The "auto" flag will only merge once all of the target branch's required checks
# are met. Configure those in the "branch protection" settings for each repo.
- name: Auto-merge dependabot PRs
if: contains(steps.metadata.outputs.package-ecosystem, 'npm') && env.MAJOR_BUMP == 'false'
if: contains(steps.metadata.outputs.package-ecosystem, 'npm') && contains(fromJSON('["version-update:semver-minor","version-update:semver-patch"]'), steps.metadata.outputs.update-type)
env:
PR_URL: ${{ github.event.pull_request.html_url }}
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
Expand Down
Loading