Skip to content

Re-pin dependabot-sync; contents: write for auto-merge arming - #473

Merged
jeremy merged 1 commit into
mainfrom
ci/repin-d7a98882
Jul 27, 2026
Merged

Re-pin dependabot-sync; contents: write for auto-merge arming#473
jeremy merged 1 commit into
mainfrom
ci/repin-d7a98882

Conversation

@jeremy

@jeremy jeremy commented Jul 27, 2026

Copy link
Copy Markdown
Member

basecamp/.github#14: round 3 passed every invariant and failed only at enablePullRequestAutoMerge (needs contents: write, the dependabot-auto-merge grant). Caller permission raised to match. This merge's push is exercise round 4 — expected to complete the cycle: adopt #466, arm auto-merge, approve held runs, auto-merge, terminal no-op, audit green.


Summary by cubic

Re-pinned the Dependabot sync workflow to commit d7a98882 and switched the job token to contents: write. This enables enablePullRequestAutoMerge so Dependabot PRs can auto-merge after approval.

Written for commit 578de7d. Summary will update on new commits.

Review in cubic

basecamp/.github#14: enablePullRequestAutoMerge needs contents: write
on the job token (round 3 passed every other gate). Exercise round 4.
Copilot AI review requested due to automatic review settings July 27, 2026 22:09
@github-actions

Copy link
Copy Markdown
Contributor

Sensitive Change Detection (shadow mode)

This PR modifies control-plane files:

  • .github/workflows/dependabot-sync-actions-comments.yml

Shadow mode — this check is informational only. When activated, changes to these paths will require approval from a maintainer.

@github-actions github-actions Bot added the github-actions Pull requests that update GitHub Actions label Jul 27, 2026
@github-actions github-actions Bot added the enhancement New feature or request label Jul 27, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Re-pins the reusable dependabot-sync-actions-comments workflow and expands the caller job’s GITHUB_TOKEN permissions to allow arming PR auto-merge from the called workflow, aligning with the described enablePullRequestAutoMerge requirement.

Changes:

  • Update the referenced reusable workflow SHA pin for dependabot-sync-actions-comments.
  • Raise job permissions from contents: read to contents: write (keeping actions: write / pull-requests: write) to enable auto-merge arming.

Tip

If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Re-trigger cubic

@jeremy
jeremy merged commit a35fe1a into main Jul 27, 2026
47 of 48 checks passed
@jeremy
jeremy deleted the ci/repin-d7a98882 branch July 27, 2026 22:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request github-actions Pull requests that update GitHub Actions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants