Compare commits

...
Author SHA1 Message Date
xixu-me ad0bb55c8c chore: reconcile rewritten main history
CI / build (push) Waiting to run
2026-08-19 17:13:01 +08:00
xixu-me 41136dedcc feat(proxy): add Google Translate route 2026-08-19 17:13:01 +08:00
xixu-me 1d7245895f fix(actions): avoid status event fan-out 2026-08-18 11:29:54 +08:00
xixu-me d89ff0361a fix(actions): avoid status event fan-out 2026-08-18 11:29:54 +08:00
xixu-me 37aee09843 fix(actions): retry Dependabot merge after checks 2026-08-18 11:25:17 +08:00
xixu-me 1762f0f34c fix(actions): retry Dependabot merge after checks 2026-08-18 11:25:17 +08:00
xixu-me 87777057d3 fix(deps): resolve Dependabot alerts 2026-08-17 12:08:08 +08:00
xixu-me 529464629f fix(deps): resolve Dependabot alerts 2026-08-17 12:08:08 +08:00
xixu-me 969dfd66f7 ci: trigger Dependabot auto-merge from workflow runs 2026-07-03 23:34:42 +08:00
xixu-me ad0789135f ci: trigger Dependabot auto-merge from workflow runs 2026-07-03 23:34:42 +08:00
xixu-me c43f50a8d8 ci: tolerate protected Dependabot workflow updates 2026-07-03 23:14:54 +08:00
xixu-me e46e608f44 ci: tolerate protected Dependabot workflow updates 2026-07-03 23:14:54 +08:00
xixu-me a3b3067fd6 ci: add Dependabot auto merge workflow 2026-07-03 23:04:13 +08:00
xixu-me 9e944e2e46 ci: add Dependabot auto merge workflow 2026-07-03 23:04:13 +08:00
xixu-me 308fded1f7 fix(deps): override esbuild to 0.28.1 2026-06-14 20:58:11 +08:00
xixu-me 93ec667406 fix(deps): override esbuild to 0.28.1 2026-06-14 20:58:11 +08:00
xixu-me 7f96bc9f63 Merge pull request #11 from xixu-me/dependabot/npm_and_yarn/npm_and_yarn-f60e9691c1
chore(deps): bump nitropack from 2.13.1 to 2.13.4 in the npm_and_yarn group across 1 directory
2026-05-08 19:26:08 +08:00
xixu-me b043faec3a Merge pull request #11 from xixu-me/dependabot/npm_and_yarn/npm_and_yarn-f60e9691c1
chore(deps): bump nitropack from 2.13.1 to 2.13.4 in the npm_and_yarn group across 1 directory
2026-05-08 19:26:08 +08:00
dependabot[bot] ce9da6a7ee chore(deps): bump nitropack in the npm_and_yarn group across 1 directory
Bumps the npm_and_yarn group with 1 update in the / directory: [nitropack](https://github.com/nitrojs/nitro).


Updates `nitropack` from 2.13.1 to 2.13.4
- [Release notes](https://github.com/nitrojs/nitro/releases)
- [Changelog](https://github.com/nitrojs/nitro/blob/main/changelog.config.ts)
- [Commits](https://github.com/nitrojs/nitro/compare/v2.13.1...v2.13.4)

---
updated-dependencies:
- dependency-name: nitropack
  dependency-version: 2.13.4
  dependency-type: direct:production
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 11:14:40 +00:00
dependabot[bot] c323e8f9fe chore(deps): bump nitropack in the npm_and_yarn group across 1 directory
Bumps the npm_and_yarn group with 1 update in the / directory: [nitropack](https://github.com/nitrojs/nitro).


Updates `nitropack` from 2.13.1 to 2.13.4
- [Release notes](https://github.com/nitrojs/nitro/releases)
- [Changelog](https://github.com/nitrojs/nitro/blob/main/changelog.config.ts)
- [Commits](https://github.com/nitrojs/nitro/compare/v2.13.1...v2.13.4)

---
updated-dependencies:
- dependency-name: nitropack
  dependency-version: 2.13.4
  dependency-type: direct:production
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 11:14:40 +00:00
xixu-me dfc2edafc7 Merge pull request #10 from xixu-me/dependabot/npm_and_yarn/npm_and_yarn-52571dc7e9
chore(deps): bump lodash from 4.17.23 to 4.18.1 in the npm_and_yarn group across 1 directory
2026-04-04 19:38:02 +08:00
xixu-me 68835ec1ab Merge pull request #10 from xixu-me/dependabot/npm_and_yarn/npm_and_yarn-52571dc7e9
chore(deps): bump lodash from 4.17.23 to 4.18.1 in the npm_and_yarn group across 1 directory
2026-04-04 19:38:02 +08:00
dependabot[bot] 52f1795b6c chore(deps): bump lodash in the npm_and_yarn group across 1 directory
Bumps the npm_and_yarn group with 1 update in the / directory: [lodash](https://github.com/lodash/lodash).


Updates `lodash` from 4.17.23 to 4.18.1
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](https://github.com/lodash/lodash/compare/4.17.23...4.18.1)

---
updated-dependencies:
- dependency-name: lodash
  dependency-version: 4.18.1
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-04 11:36:21 +00:00
dependabot[bot] 40c2bfa514 chore(deps): bump lodash in the npm_and_yarn group across 1 directory
Bumps the npm_and_yarn group with 1 update in the / directory: [lodash](https://github.com/lodash/lodash).


Updates `lodash` from 4.17.23 to 4.18.1
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](https://github.com/lodash/lodash/compare/4.17.23...4.18.1)

---
updated-dependencies:
- dependency-name: lodash
  dependency-version: 4.18.1
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-04 11:36:21 +00:00
xixu-me 08adfc45a5 Merge pull request #9 from xixu-me/dependabot/npm_and_yarn/npm_and_yarn-47ab31ee9e
chore(deps): bump defu from 6.1.4 to 6.1.6 in the npm_and_yarn group across 1 directory
2026-04-04 19:35:10 +08:00
xixu-me c53794701f Merge pull request #9 from xixu-me/dependabot/npm_and_yarn/npm_and_yarn-47ab31ee9e
chore(deps): bump defu from 6.1.4 to 6.1.6 in the npm_and_yarn group across 1 directory
2026-04-04 19:35:10 +08:00
xixu-me 7957303b4c ci: ignore unfixable audit advisories 2026-04-04 19:31:47 +08:00
xixu-me 74d9c81245 ci: ignore unfixable audit advisories 2026-04-04 19:31:47 +08:00
dependabot[bot] cc3f85d9e4 chore(deps): bump defu in the npm_and_yarn group across 1 directory
Bumps the npm_and_yarn group with 1 update in the / directory: [defu](https://github.com/unjs/defu).


Updates `defu` from 6.1.4 to 6.1.6
- [Release notes](https://github.com/unjs/defu/releases)
- [Changelog](https://github.com/unjs/defu/blob/main/CHANGELOG.md)
- [Commits](https://github.com/unjs/defu/compare/v6.1.4...v6.1.6)

---
updated-dependencies:
- dependency-name: defu
  dependency-version: 6.1.6
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-04 07:36:03 +00:00
dependabot[bot] dbbcfa2bfe chore(deps): bump defu in the npm_and_yarn group across 1 directory
Bumps the npm_and_yarn group with 1 update in the / directory: [defu](https://github.com/unjs/defu).


Updates `defu` from 6.1.4 to 6.1.6
- [Release notes](https://github.com/unjs/defu/releases)
- [Changelog](https://github.com/unjs/defu/blob/main/CHANGELOG.md)
- [Commits](https://github.com/unjs/defu/compare/v6.1.4...v6.1.6)

---
updated-dependencies:
- dependency-name: defu
  dependency-version: 6.1.6
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-04 07:36:03 +00:00
xixu-me 324bc53099 Merge branch 'main' of https://github.com/xixu-me/xdpl 2026-03-28 20:18:48 +08:00
xixu-me dafc9768c3 fix(deps): patch serialize-javascript vulnerability 2026-03-28 20:17:21 +08:00
xixu-me cdc37bb412 Merge pull request #8 from xixu-me/dependabot/npm_and_yarn/npm_and_yarn-4699359277
chore(deps): bump node-forge from 1.3.3 to 1.4.0 in the npm_and_yarn group across 1 directory
2026-03-28 13:32:06 +08:00
dependabot[bot] b50c3603af chore(deps): bump node-forge
Bumps the npm_and_yarn group with 1 update in the / directory: [node-forge](https://github.com/digitalbazaar/forge).


Updates `node-forge` from 1.3.3 to 1.4.0
- [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md)
- [Commits](https://github.com/digitalbazaar/forge/compare/v1.3.3...v1.4.0)

---
updated-dependencies:
- dependency-name: node-forge
  dependency-version: 1.4.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-03-27 15:25:56 +00:00
xixu-me d99467b4ae Merge pull request #7 from xixu-me/dependabot/npm_and_yarn/npm_and_yarn-534ef04cac
chore(deps): bump brace-expansion from 2.0.2 to 2.0.3 in the npm_and_yarn group across 1 directory
2026-03-27 23:00:13 +08:00
dependabot[bot] 64e5cbb3d6 chore(deps): bump brace-expansion
Bumps the npm_and_yarn group with 1 update in the / directory: [brace-expansion](https://github.com/juliangruber/brace-expansion).


Updates `brace-expansion` from 2.0.2 to 2.0.3
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v2.0.2...v2.0.3)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 2.0.3
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-03-27 14:50:49 +00:00
xixu-me 65f2c97a3e Merge pull request #6 from xixu-me/dependabot/npm_and_yarn/npm_and_yarn-66413a1f6e
chore(deps): bump picomatch from 2.3.1 to 2.3.2 in the npm_and_yarn group across 1 directory
2026-03-26 16:57:30 +08:00
dependabot[bot] 754ce9fc72 chore(deps): bump picomatch in the npm_and_yarn group across 1 directory
Bumps the npm_and_yarn group with 1 update in the / directory: [picomatch](https://github.com/micromatch/picomatch).


Updates `picomatch` from 2.3.1 to 2.3.2
- [Release notes](https://github.com/micromatch/picomatch/releases)
- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md)
- [Commits](https://github.com/micromatch/picomatch/compare/2.3.1...2.3.2)

---
updated-dependencies:
- dependency-name: picomatch
  dependency-version: 2.3.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-03-26 08:55:37 +00:00
xixu-me 3791f34e08 Merge pull request #5 from xixu-me/dependabot/npm_and_yarn/npm_and_yarn-880b646042
chore(deps): bump h3 from 1.15.6 to 1.15.9 in the npm_and_yarn group across 1 directory
2026-03-21 17:10:15 +08:00
dependabot[bot] 051a5cc8b5 chore(deps): bump h3 in the npm_and_yarn group across 1 directory
Bumps the npm_and_yarn group with 1 update in the / directory: [h3](https://github.com/h3js/h3).


Updates `h3` from 1.15.6 to 1.15.9
- [Release notes](https://github.com/h3js/h3/releases)
- [Changelog](https://github.com/h3js/h3/blob/v1.15.9/CHANGELOG.md)
- [Commits](https://github.com/h3js/h3/compare/v1.15.6...v1.15.9)

---
updated-dependencies:
- dependency-name: h3
  dependency-version: 1.15.9
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-03-21 09:07:32 +00:00
xixu-me 2f76987bd9 chore: harden dependabot updates 2026-03-17 15:13:01 +08:00
xixu-me 7b012e7f55 Merge pull request #4 from xixu-me/dependabot/npm_and_yarn/npm_and_yarn-876b851ef1
chore(deps): bump rollup from 3.29.5 to 3.30.0 in the npm_and_yarn group across 1 directory
2026-02-26 15:52:00 +08:00
dependabot[bot] 61bc9d45c2 chore(deps): bump rollup in the npm_and_yarn group across 1 directory
Bumps the npm_and_yarn group with 1 update in the / directory: [rollup](https://github.com/rollup/rollup).


Updates `rollup` from 3.29.5 to 3.30.0
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/v3.30.0/CHANGELOG.md)
- [Commits](https://github.com/rollup/rollup/compare/v3.29.5...v3.30.0)

---
updated-dependencies:
- dependency-name: rollup
  dependency-version: 3.30.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-26 07:44:53 +00:00
xixu-me 5b286d9fe2 Merge pull request #3 from xixu-me/dependabot/npm_and_yarn/npm_and_yarn-c7796958eb
chore(deps): bump minimatch from 3.1.2 to 3.1.4 in the npm_and_yarn group across 1 directory
2026-02-25 18:00:20 +08:00
dependabot[bot] 0cc2eaba8f chore(deps): bump minimatch in the npm_and_yarn group across 1 directory
Bumps the npm_and_yarn group with 1 update in the / directory: [minimatch](https://github.com/isaacs/minimatch).


Updates `minimatch` from 3.1.2 to 3.1.4
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](https://github.com/isaacs/minimatch/compare/v3.1.2...v3.1.4)

---
updated-dependencies:
- dependency-name: minimatch
  dependency-version: 3.1.4
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-25 09:57:56 +00:00
xixu-me faa8fd6950 Merge pull request #2 from xixu-me/dependabot/npm_and_yarn/npm_and_yarn-b83c1950df
chore(deps): bump h3 from 1.8.1 to 1.15.5 in the npm_and_yarn group across 1 directory
2026-01-16 05:43:24 +08:00
dependabot[bot] c842419620 chore(deps): bump h3 in the npm_and_yarn group across 1 directory
Bumps the npm_and_yarn group with 1 update in the / directory: [h3](https://github.com/h3js/h3).


Updates `h3` from 1.8.1 to 1.15.5
- [Release notes](https://github.com/h3js/h3/releases)
- [Changelog](https://github.com/h3js/h3/blob/v1.15.5/CHANGELOG.md)
- [Commits](https://github.com/h3js/h3/compare/v1.8.1...v1.15.5)

---
updated-dependencies:
- dependency-name: h3
  dependency-version: 1.15.5
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-01-15 21:01:02 +00:00
xixu-me 5e09be253f Merge pull request #1 from xixu-me/dependabot/npm_and_yarn/npm_and_yarn-64d2a2babc
chore(deps): bump the npm_and_yarn group across 1 directory with 12 updates
2025-12-07 00:09:34 +08:00
dependabot[bot] 3c5b7b7c2f chore(deps): bump the npm_and_yarn group across 1 directory with 12 updates
Bumps the npm_and_yarn group with 12 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.12` |
| [braces](https://github.com/micromatch/braces) | `3.0.2` | `3.0.3` |
| [cross-spawn](https://github.com/moxystudio/node-cross-spawn) | `7.0.3` | `7.0.6` |
| [esbuild](https://github.com/evanw/esbuild) | `0.19.2` | `0.19.12` |
| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.0` | `4.1.1` |
| [micromatch](https://github.com/micromatch/micromatch) | `4.0.5` | `4.0.8` |
| [node-forge](https://github.com/digitalbazaar/forge) | `1.3.1` | `1.3.3` |
| [rollup](https://github.com/rollup/rollup) | `3.28.1` | `3.29.5` |
| [serialize-javascript](https://github.com/yahoo/serialize-javascript) | `6.0.1` | `6.0.2` |
| [serve-static](https://github.com/expressjs/serve-static) | `1.15.0` | `1.16.2` |
| [tar](https://github.com/isaacs/node-tar) | `6.1.15` | `6.2.1` |
| [undici](https://github.com/nodejs/undici) | `5.23.0` | `5.29.0` |



Updates `brace-expansion` from 1.1.11 to 1.1.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/1.1.11...v1.1.12)

Updates `braces` from 3.0.2 to 3.0.3
- [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md)
- [Commits](https://github.com/micromatch/braces/compare/3.0.2...3.0.3)

Updates `cross-spawn` from 7.0.3 to 7.0.6
- [Changelog](https://github.com/moxystudio/node-cross-spawn/blob/master/CHANGELOG.md)
- [Commits](https://github.com/moxystudio/node-cross-spawn/compare/v7.0.3...v7.0.6)

Updates `esbuild` from 0.19.2 to 0.19.12
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/v0.19.12/CHANGELOG.md)
- [Commits](https://github.com/evanw/esbuild/compare/v0.19.2...v0.19.12)

Updates `js-yaml` from 4.1.0 to 4.1.1
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.1.0...4.1.1)

Updates `micromatch` from 4.0.5 to 4.0.8
- [Release notes](https://github.com/micromatch/micromatch/releases)
- [Changelog](https://github.com/micromatch/micromatch/blob/master/CHANGELOG.md)
- [Commits](https://github.com/micromatch/micromatch/compare/4.0.5...4.0.8)

Updates `node-forge` from 1.3.1 to 1.3.3
- [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md)
- [Commits](https://github.com/digitalbazaar/forge/compare/v1.3.1...v1.3.3)

Updates `rollup` from 3.28.1 to 3.29.5
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG-3.md)
- [Commits](https://github.com/rollup/rollup/compare/v3.28.1...v3.29.5)

Updates `serialize-javascript` from 6.0.1 to 6.0.2
- [Release notes](https://github.com/yahoo/serialize-javascript/releases)
- [Commits](https://github.com/yahoo/serialize-javascript/compare/v6.0.1...v6.0.2)

Updates `serve-static` from 1.15.0 to 1.16.2
- [Release notes](https://github.com/expressjs/serve-static/releases)
- [Changelog](https://github.com/expressjs/serve-static/blob/v1.16.2/HISTORY.md)
- [Commits](https://github.com/expressjs/serve-static/compare/v1.15.0...v1.16.2)

Updates `tar` from 6.1.15 to 6.2.1
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](https://github.com/isaacs/node-tar/compare/v6.1.15...v6.2.1)

Updates `undici` from 5.23.0 to 5.29.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](https://github.com/nodejs/undici/compare/v5.23.0...v5.29.0)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.12
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: braces
  dependency-version: 3.0.3
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: cross-spawn
  dependency-version: 7.0.6
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: esbuild
  dependency-version: 0.19.12
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: js-yaml
  dependency-version: 4.1.1
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: micromatch
  dependency-version: 4.0.8
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: node-forge
  dependency-version: 1.3.3
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: rollup
  dependency-version: 3.29.5
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: serialize-javascript
  dependency-version: 6.0.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: serve-static
  dependency-version: 1.16.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: tar
  dependency-version: 6.2.1
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: undici
  dependency-version: 5.29.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-06 16:07:46 +00:00
xixu-me 9b95825a23 Add data privacy and security section to README
Introduced a new section detailing data privacy, security features, best practices, and compliance considerations for the proxy. This provides users with clear information on how data is handled and how to securely deploy the project.
2025-07-21 13:15:45 +08:00
xixu-me 63c9553dab Update README with corrected repo name and formatting
Changed repository references from 'xdpl' to 'XDPL' for consistency and updated code block indentation for improved readability in setup and deployment instructions.
2025-07-21 11:09:01 +08:00
xixu-me 4875568f8d Add project README with setup and usage details
Introduces a comprehensive README.md describing XDPL, its features, tech stack, installation steps, usage instructions, deployment options, and configuration. This provides essential documentation for new users and contributors.
2025-07-19 23:38:48 +08:00
xixu-me a7e5c95029 Update DeepL proxy target and cleanup project files
Changed proxy target in nitro.config.ts from api-free.deepl.com to www2.deepl.com. Removed README.md and reformatted .eslintrc. Reordered scripts in package.json for consistency.
2025-07-19 23:05:52 +08:00
Qin Guan ee98793e47 chore: add license 2024-03-20 01:14:54 +08:00
5 changed files with 1102 additions and 859 deletions

No files matched your search

+1 -1
View File
@@ -34,7 +34,7 @@ jobs:
run: pnpm install --frozen-lockfile run: pnpm install --frozen-lockfile
- name: Audit production dependencies - name: Audit production dependencies
run: pnpm audit --prod --audit-level=high run: pnpm audit --prod --audit-level=high --ignore-unfixable
- name: Build Nitro app - name: Build Nitro app
run: pnpm build run: pnpm build
+202 -23
View File
@@ -1,38 +1,217 @@
name: Dependabot Auto Merge name: Dependabot Auto Merge
on: on:
pull_request: schedule:
- cron: "43 3 * * *"
check_suite:
types: [completed]
workflow_run:
workflows:
- "CI"
- "CodeQL"
- "Dependabot Updates"
types: types:
- opened - completed
- synchronize workflow_dispatch:
- reopened
- labeled concurrency:
group: ${{ github.workflow }}-${{ github.event.workflow_run.head_branch || github.run_id }}
cancel-in-progress: false
permissions: permissions:
contents: write contents: write
pull-requests: write pull-requests: write
checks: read
statuses: read
jobs: jobs:
enable-automerge: merge:
if: github.event.pull_request.user.login == 'dependabot[bot]' name: Auto-merge Dependabot PRs
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 10 timeout-minutes: 10
steps: steps:
- name: Fetch Dependabot metadata - name: Merge Dependabot PRs when checks pass
id: metadata uses: actions/github-script@v9
uses: dependabot/fetch-metadata@d7267f607e9d3fb96fc2fbe83e0af444713e90b7
with: with:
github-token: ${{ secrets.GITHUB_TOKEN }} script: |
const owner = context.repo.owner;
const repo = context.repo.repo;
- name: Enable auto-merge for patch updates const successfulCheckConclusions = new Set(["success", "skipped", "neutral"]);
if: | const successfulStatusStates = new Set(["success"]);
(github.event.pull_request.base.ref == 'main') && const wait = (ms) => new Promise((resolve) => setTimeout(resolve, ms));
(
steps.metadata.outputs.update-type == 'version-update:semver-patch' || const latestBy = (items, keyOf, timeOf) => {
steps.metadata.outputs.update-type == 'security:update' const latest = new Map();
) for (const item of items) {
run: gh pr merge --auto --merge "$PR_URL" const key = keyOf(item);
env: const itemTime = new Date(timeOf(item) || 0).getTime();
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} const existing = latest.get(key);
PR_URL: ${{ github.event.pull_request.html_url }} const existingTime = existing ? new Date(timeOf(existing) || 0).getTime() : -1;
if (!existing || itemTime >= existingTime) {
latest.set(key, item);
}
}
return [...latest.values()];
};
const findCandidatePulls = async () => {
const branch = context.payload.workflow_run?.head_branch;
if (context.eventName === "workflow_run" && branch) {
const { data: pulls } = await github.rest.pulls.list({
owner,
repo,
state: "open",
head: owner + ":" + branch,
per_page: 10,
});
return pulls.filter((pr) => pr.user?.login === "dependabot[bot]");
}
const pulls = await github.paginate(github.rest.pulls.list, {
owner,
repo,
state: "open",
per_page: 100,
});
return pulls.filter((pr) => pr.user?.login === "dependabot[bot]");
};
const getMergeablePullRequest = async (pull_number) => {
for (let attempt = 1; attempt <= 6; attempt += 1) {
const { data: pr } = await github.rest.pulls.get({ owner, repo, pull_number });
if (pr.mergeable !== null) {
return pr;
}
core.info("PR #" + pull_number + " mergeability is still being computed; retry " + attempt + "/6.");
await wait(5000);
}
const { data: pr } = await github.rest.pulls.get({ owner, repo, pull_number });
return pr;
};
const getSignalState = async (sha) => {
const checkRuns = await github.paginate(github.rest.checks.listForRef, {
owner,
repo,
ref: sha,
per_page: 100,
});
const statuses = await github.paginate(github.rest.repos.listCommitStatusesForRef, {
owner,
repo,
ref: sha,
per_page: 100,
});
const latestChecks = latestBy(
checkRuns.filter((run) => run.name !== "Dependabot Auto Merge"),
(run) => (run.app?.slug || "unknown") + ":" + run.name,
(run) => run.completed_at || run.started_at || run.created_at,
);
const latestStatuses = latestBy(statuses, (status) => status.context, (status) => status.updated_at || status.created_at);
const pendingChecks = latestChecks.filter((run) => run.status !== "completed");
const failedChecks = latestChecks.filter(
(run) => run.status === "completed" && !successfulCheckConclusions.has(String(run.conclusion || "").toLowerCase()),
);
const failedStatuses = latestStatuses.filter((status) => !successfulStatusStates.has(String(status.state || "").toLowerCase()));
return {
totalSignals: latestChecks.length + latestStatuses.length,
pendingChecks,
failedChecks,
failedStatuses,
};
};
const { data: repository } = await github.rest.repos.get({ owner, repo });
const mergeMethods = [];
if (repository.allow_merge_commit) mergeMethods.push("merge");
if (repository.allow_squash_merge) mergeMethods.push("squash");
if (repository.allow_rebase_merge) mergeMethods.push("rebase");
if (mergeMethods.length === 0) {
core.info("This repository has no enabled pull request merge methods.");
return;
}
const pulls = await findCandidatePulls();
if (pulls.length === 0) {
core.info("No open Dependabot PRs to evaluate.");
return;
}
for (const candidate of pulls) {
const pull_number = candidate.number;
const pr = await getMergeablePullRequest(pull_number);
if (pr.user?.login !== "dependabot[bot]") {
core.info("PR #" + pull_number + " is no longer a Dependabot PR.");
continue;
}
if (pr.state !== "open" || pr.draft) {
core.info("PR #" + pull_number + " is not an open, ready PR.");
continue;
}
if (pr.mergeable !== true) {
core.info("PR #" + pull_number + " is not currently mergeable.");
continue;
}
const signalState = await getSignalState(pr.head.sha);
if (signalState.totalSignals === 0) {
core.info("PR #" + pull_number + " has no checks or statuses yet; skipping.");
continue;
}
if (signalState.pendingChecks.length > 0) {
core.info("PR #" + pull_number + " still has pending checks: " + signalState.pendingChecks.map((run) => run.name).join(", ") + ".");
continue;
}
if (signalState.failedChecks.length > 0 || signalState.failedStatuses.length > 0) {
const failedChecks = signalState.failedChecks.map((run) => run.name + "=" + run.conclusion).join(", ");
const failedStatuses = signalState.failedStatuses.map((status) => status.context + "=" + status.state).join(", ");
core.info("PR #" + pull_number + " is not green. Checks: " + (failedChecks || "none") + ". Statuses: " + (failedStatuses || "none") + ".");
continue;
}
let merged = false;
let lastError = null;
for (const merge_method of mergeMethods) {
try {
await github.rest.pulls.merge({ owner, repo, pull_number, merge_method });
core.info("Merged Dependabot PR #" + pull_number + " with " + merge_method + ".");
merged = true;
break;
} catch (error) {
lastError = error;
if (error.status === 403 || error.status === 405 || error.status === 409) {
core.info("Cannot merge PR #" + pull_number + " with " + merge_method + ": " + error.message);
continue;
}
throw error;
}
}
if (!merged) {
core.info("PR #" + pull_number + " could not be merged: " + (lastError?.message || "unknown error") + ".");
continue;
}
if (pr.head.repo?.full_name === owner + "/" + repo) {
try {
await github.rest.git.deleteRef({ owner, repo, ref: "heads/" + pr.head.ref });
core.info("Deleted branch " + pr.head.ref + ".");
} catch (error) {
core.info("Could not delete branch " + pr.head.ref + ": " + error.message);
}
}
}
+3
View File
@@ -2,6 +2,9 @@
export default defineNitroConfig({ export default defineNitroConfig({
compatibilityDate: "2026-03-17", compatibilityDate: "2026-03-17",
routeRules: { routeRules: {
"/google/**": {
proxy: "https://translate.googleapis.com/**",
},
"/**": { "/**": {
proxy: "https://www2.deepl.com/**", proxy: "https://www2.deepl.com/**",
}, },
+3 -2
View File
@@ -1,11 +1,12 @@
{ {
"packageManager": "pnpm@10.32.1", "packageManager": "pnpm@10.32.1",
"dependencies": { "dependencies": {
"nitropack": "2.13.1" "nitropack": "2.13.4"
}, },
"pnpm": { "pnpm": {
"overrides": { "overrides": {
"serialize-javascript": "7.0.5" "serialize-javascript": "7.0.5",
"esbuild": "0.28.1"
} }
}, },
"private": true, "private": true,
+893 -833
View File
File diff suppressed because it is too large. Load diff