fix: stop dependabot auto-merge from landing breaking majors
Root causes (this round):
- dependabot.yml had been overwritten to a minimal version with NO
ignore rules -> major bumps allowed (typescript 7, eslint 10, tsparticles 4)
- main branch had NO branch protection -> 'gh pr merge --auto' merged
even with failing CI
- auto-merge workflow had no check-run verification step
Fixes:
- Branch protection on main: required status check 'lint + typecheck +
test + build' (strict) so auto-merge cannot land failing changes
- dependabot-auto-merge.yml: verify CI check-run conclusion == success
(actions/github-script poll with timeout) before enabling auto-merge
- dependabot.yml: restore ignore rules for eslint/typescript/@tsparticles
majors + eslint-config-next + eslint-plugin-react
- Rollback toolchain to known-good exact pins:
typescript 6.0.3, eslint 9.39.5, @tsparticles/{react,engine,slim} 3.x
(exact versions, no ranges dependabot can widen)
- Close dependabot PR #19 (tsparticles 4.4.0)
This commit is contained in:
@@ -1,16 +1,53 @@
|
|||||||
name: Dependabot Auto-Merge
|
name: Dependabot Auto-Merge
|
||||||
|
|
||||||
on: pull_request
|
on: pull_request
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: write
|
contents: write
|
||||||
pull-requests: write
|
pull-requests: write
|
||||||
|
checks: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
auto-merge:
|
auto-merge:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
if: github.actor == 'dependabot[bot]'
|
if: github.actor == 'dependabot[bot]'
|
||||||
steps:
|
steps:
|
||||||
|
- name: Verify CI check-runs before enabling auto-merge
|
||||||
|
uses: actions/github-script@v7
|
||||||
|
with:
|
||||||
|
script: |
|
||||||
|
const owner = context.repo.owner;
|
||||||
|
const repo = context.repo.repo;
|
||||||
|
const sha = context.payload.pull_request.head.sha;
|
||||||
|
|
||||||
|
// Wait for in-progress runs (with timeout), then collect conclusions
|
||||||
|
const requiredContext = "lint + typecheck + test + build";
|
||||||
|
let conclusion = null;
|
||||||
|
for (let attempt = 0; attempt < 60; attempt++) {
|
||||||
|
const { data: checks } = await github.rest.checks.listForRef({
|
||||||
|
owner, repo, ref: sha,
|
||||||
|
});
|
||||||
|
const match = checks.check_runs.find(
|
||||||
|
(r) => r.name === requiredContext || r.output?.title === requiredContext
|
||||||
|
);
|
||||||
|
if (match && match.status === "completed") {
|
||||||
|
conclusion = match.conclusion;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
await new Promise((r) => setTimeout(r, 10000));
|
||||||
|
}
|
||||||
|
if (!conclusion) {
|
||||||
|
core.setFailed(`Required check "${requiredContext}" never completed within timeout.`);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
if (conclusion !== "success") {
|
||||||
|
core.setFailed(`Required check "${requiredContext}" concluded ${conclusion}. NOT merging.`);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
core.info(`Check "${requiredContext}" passed — safe to enable auto-merge.`);
|
||||||
|
|
||||||
- name: Enable auto-merge for Dependabot PR
|
- name: Enable auto-merge for Dependabot PR
|
||||||
|
if: success()
|
||||||
run: gh pr merge --auto --merge "$PR_URL"
|
run: gh pr merge --auto --merge "$PR_URL"
|
||||||
env:
|
env:
|
||||||
PR_URL: ${{ github.event.pull_request.html_url }}
|
PR_URL: ${{ github.event.pull_request.html_url }}
|
||||||
|
|||||||
@@ -5,6 +5,8 @@ updates:
|
|||||||
schedule:
|
schedule:
|
||||||
interval: "daily"
|
interval: "daily"
|
||||||
open-pull-requests-limit: 10
|
open-pull-requests-limit: 10
|
||||||
|
labels:
|
||||||
|
- "dependencies"
|
||||||
groups:
|
groups:
|
||||||
production:
|
production:
|
||||||
dependency-type: "production"
|
dependency-type: "production"
|
||||||
@@ -16,3 +18,40 @@ updates:
|
|||||||
update-types:
|
update-types:
|
||||||
- "minor"
|
- "minor"
|
||||||
- "patch"
|
- "patch"
|
||||||
|
ignore:
|
||||||
|
# ---- Toolchain pins: semver-major bumps break the lint/typecheck stack ----
|
||||||
|
# ESLint 10 dropped rule-context getFilename(); eslint-plugin-react (^7.37.x)
|
||||||
|
# peer range caps at eslint ^9.7 -> react/display-name crash at load.
|
||||||
|
- dependency-name: "eslint"
|
||||||
|
update-types: ["version-update:semver-major"]
|
||||||
|
# typescript-eslint 8.x peer range is ">=4.8.4 <6.1.0" -> TS 7 hard-refuses.
|
||||||
|
- dependency-name: "typescript"
|
||||||
|
update-types: ["version-update:semver-major"]
|
||||||
|
# @tsparticles v4 changed its exported API; the vendored SparklesCore from the
|
||||||
|
# Aceternity registry targets the v3 API (initParticlesEngine, IEffect.fill...).
|
||||||
|
# NOTE: dependabot `ignore` does NOT support wildcards (only `groups` does) —
|
||||||
|
# list each exact scoped package.
|
||||||
|
- dependency-name: "@tsparticles/react"
|
||||||
|
update-types: ["version-update:semver-major"]
|
||||||
|
- dependency-name: "@tsparticles/engine"
|
||||||
|
update-types: ["version-update:semver-major"]
|
||||||
|
- dependency-name: "@tsparticles/slim"
|
||||||
|
update-types: ["version-update:semver-major"]
|
||||||
|
# eslint-config-next majors follow Next.js majors and can pull incompatible
|
||||||
|
# plugin versions; framework majors are deliberate, not auto-bumps.
|
||||||
|
- dependency-name: "eslint-config-next"
|
||||||
|
update-types: ["version-update:semver-major"]
|
||||||
|
# eslint-plugin-react 8.x targets ESLint 10, which conflicts with the
|
||||||
|
# pinned eslint 9 (and the vendored components' validated toolchain).
|
||||||
|
- dependency-name: "eslint-plugin-react"
|
||||||
|
update-types: ["version-update:semver-major"]
|
||||||
|
- package-ecosystem: "github-actions"
|
||||||
|
directory: "/"
|
||||||
|
schedule:
|
||||||
|
interval: "weekly"
|
||||||
|
groups:
|
||||||
|
actions:
|
||||||
|
patterns: ["*"]
|
||||||
|
update-types:
|
||||||
|
- "minor"
|
||||||
|
- "patch"
|
||||||
|
|||||||
+5
-5
@@ -34,9 +34,9 @@
|
|||||||
"@tabler/icons-react": "^3.47.0",
|
"@tabler/icons-react": "^3.47.0",
|
||||||
"@tanstack/react-query": "^5.103.1",
|
"@tanstack/react-query": "^5.103.1",
|
||||||
"@tanstack/react-table": "^9.2.4",
|
"@tanstack/react-table": "^9.2.4",
|
||||||
"@tsparticles/engine": "~3.9.0",
|
"@tsparticles/engine": "3.9.1",
|
||||||
"@tsparticles/react": "~3.0.0",
|
"@tsparticles/react": "3.0.0",
|
||||||
"@tsparticles/slim": "~4.4.0",
|
"@tsparticles/slim": "3.9.1",
|
||||||
"better-auth": "^1.7.5",
|
"better-auth": "^1.7.5",
|
||||||
"class-variance-authority": "^0.7.1",
|
"class-variance-authority": "^0.7.1",
|
||||||
"clsx": "^2.1.1",
|
"clsx": "^2.1.1",
|
||||||
@@ -81,7 +81,7 @@
|
|||||||
"@types/react": "^19",
|
"@types/react": "^19",
|
||||||
"@types/react-dom": "^19",
|
"@types/react-dom": "^19",
|
||||||
"@vitest/coverage-v8": "^5.0.1",
|
"@vitest/coverage-v8": "^5.0.1",
|
||||||
"eslint": ">=9.24.0 <11",
|
"eslint": "9.39.5",
|
||||||
"eslint-config-next": "16.3.5",
|
"eslint-config-next": "16.3.5",
|
||||||
"eslint-plugin-react": "^7.37.5",
|
"eslint-plugin-react": "^7.37.5",
|
||||||
"husky": "^9.1.7",
|
"husky": "^9.1.7",
|
||||||
@@ -91,7 +91,7 @@
|
|||||||
"prettier": "^3.9.8",
|
"prettier": "^3.9.8",
|
||||||
"prettier-plugin-tailwindcss": "^0.8.1",
|
"prettier-plugin-tailwindcss": "^0.8.1",
|
||||||
"tailwindcss": "^4",
|
"tailwindcss": "^4",
|
||||||
"typescript": "^7.0.2",
|
"typescript": "6.0.3",
|
||||||
"typescript-eslint": "^8.70.0",
|
"typescript-eslint": "^8.70.0",
|
||||||
"vitest": "^5.0.1"
|
"vitest": "^5.0.1"
|
||||||
},
|
},
|
||||||
|
|||||||
Reference in New Issue
Block a user