ci(deps): Dependabot grouping + /tests/git-sync coverage (#1243) - #1244
Conversation
Adds .github/workflows/dependabot-auto-merge.yml — zero-touch merge for Dependabot semver patch/minor only (all majors held). Gates on build + pytest in-workflow; a machine PAT (DEPENDABOT_AUTOMERGE_TOKEN, stored as a Dependabot secret) supplies the required approval since GITHUB_TOKEN can't, then --auto --squash (CodeQL still enforced by branch protection). dependabot.yml: group github-actions bumps into one weekly PR; cover the previously-uncovered /tests/git-sync npm dir (source of esbuild alert #152). Refs #1243 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Concern: this enables zero-touch merges directly to
|
Per dolho's review on #1244: a Dependabot security update auto-merged to main could trip publish-cli.yml (push to main + src/cli/** -> auto patch-bump -> PyPI publish) unattended. Add a base.ref == 'dev' job guard so the workflow is structurally incapable of acting on main-targeted PRs, even once a release carries this file onto main. Main security PRs are merged manually. Refs #1243 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…flow (review #1244) Per dolho's review and the conscious decision on #1243: auto-merge is dev-only. main must NOT carry zero-touch merge machinery (a security PR to main could auto-publish trinity-cli to PyPI unattended). This PR now ships only the dependabot.yml grouping + /tests/git-sync coverage, which must live on main since Dependabot reads config from the default branch. The (dev-guarded) workflow reaches main later via the normal release, inert for main PRs. Refs #1243 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Confirmed and adopted — thank you, this is a sharp catch. We traced
So a security PR for a vulnerable dep in Decision (option 3): auto-merge is dev-only.
Your risks #1 (back-merge) and #2 (security-only + full-suite + exclude |
Fixes #1243 (canonical landing —
dependabot.ymlis read from the default branch, so the grouping/coverage changes only take effect once this lands onmain).What this does
Layer 1 —
.github/workflows/dependabot-auto-merge.ymlbuild+ everypytestcheck to be green in-workflow (path-filtered PRs with neither check fall back to the required CodeQL gate via--auto).enforce_admins: trueand the ActionsGITHUB_TOKENcan't supply a counting approval — so a machine PAT (DEPENDABOT_AUTOMERGE_TOKEN, a Dependabot secret) approves eligible green PRs, thengh pr merge --auto --squash.Layer 2 —
.github/dependabot.ymlgithub-actionsbumps into one weekly PR (was one PR per action)./tests/git-syncnpm dir — source of esbuild alert fix: Guard stream-json parser against non-dict JSON lines (#151) #152.Activation (manual — required, only a human can do it)
Abilityai/trinitywith Pull requests: read/write + Contents: read/write.gh secret set DEPENDABOT_AUTOMERGE_TOKEN --app dependabot --repo Abilityai/trinity(Dependabot store, NOT Actions).allow_auto_mergeenabled (done out-of-band).Until the secret exists the final step no-ops with a warning — nothing merges.
Not in this PR (Layer 3, follow-up)
Weekly triage process +
main → devback-merge so security PRs (which land onmain) don't stranddev. Tracked in #1243.