diff --git a/.github/dependabot-auto-merge.yml b/.github/dependabot-auto-merge.yml index 7f78348..b36eb6f 100644 --- a/.github/dependabot-auto-merge.yml +++ b/.github/dependabot-auto-merge.yml @@ -4,14 +4,41 @@ on: pull_request permissions: contents: write pull-requests: write + checks: read jobs: auto-merge: runs-on: ubuntu-latest + # Only for dependabot PRs whose CI is green: the "CI" workflow must have + # completed successfully before auto-merge is enabled. Without this guard, + # gh pr merge --auto merges as soon as checks finish — including failures + # (breaking bumps like eslint@10 / tsparticles@4 / typescript@7 landed + # repeatedly because of that). if: github.actor == 'dependabot[bot]' steps: + - name: Wait for CI checks to pass + uses: actions/github-script@v7 + with: + script: | + const { data: checks } = await github.rest.checks.listForRef({ + owner: context.repo.owner, + repo: context.repo.repo, + ref: context.payload.pull_request.head.sha, + }); + const pending = checks.check_runs.filter((c) => c.status !== "completed"); + if (pending.length > 0) { + core.setFailed(`CI not finished yet: ${pending.map((c) => c.name).join(", ")}`); + return; + } + const failed = checks.check_runs.filter((c) => c.conclusion === "failure"); + if (failed.length > 0) { + core.setFailed(`CI failed: ${failed.map((c) => c.name).join(", ")}`); + return; + } + core.notice(`All ${checks.check_runs.length} checks passed — enabling auto-merge.`); + - name: Enable auto-merge for Dependabot PR run: gh pr merge --auto --merge "$PR_URL" env: PR_URL: ${{ github.event.pull_request.html_url }} - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} \ No newline at end of file