diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 94ca836..2b13723 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -14,6 +14,13 @@ updates: - dependencies open-pull-requests-limit: 10 rebase-strategy: auto + ignore: + - dependency-name: koa + update-types: + - version-update:semver-major + - dependency-name: "@types/koa" + update-types: + - version-update:semver-major groups: production-dependencies: dependency-type: production @@ -40,6 +47,10 @@ updates: - dependencies - docker open-pull-requests-limit: 5 + ignore: + - dependency-name: node + update-types: + - version-update:semver-major - package-ecosystem: github-actions directory: / diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index 80c262e..6f1c3bc 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -23,6 +23,16 @@ jobs: PR_URL: ${{ github.event.pull_request.html_url }} run: gh pr review --repo "$GITHUB_REPOSITORY" "$PR_URL" --approve --body "Approved automatically after policy checks." || true + - name: Update stale Dependabot branches + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + PR_URL: ${{ github.event.pull_request.html_url }} + run: | + merge_state="$(gh pr view --repo "$GITHUB_REPOSITORY" "$PR_URL" --json mergeStateStatus --jq .mergeStateStatus)" + if [ "$merge_state" = "BEHIND" ]; then + gh pr update-branch --repo "$GITHUB_REPOSITORY" "$PR_URL" + fi + - name: Enable auto-merge after required checks pass env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/tests/github-automation.test.cjs b/tests/github-automation.test.cjs index 042656f..2294b9d 100644 --- a/tests/github-automation.test.cjs +++ b/tests/github-automation.test.cjs @@ -53,6 +53,14 @@ test('dependabot config covers npm, docker, and github-actions updates', () => { assert.match(dependabot, /package-ecosystem: github-actions/); }); +test('dependabot ignores unsupported major upgrades for koa and docker base images', () => { + const dependabot = read('.github/dependabot.yml'); + + assert.match(dependabot, /dependency-name:\s*koa/); + assert.match(dependabot, /update-types:\s*\n\s*- version-update:semver-major/); + assert.match(dependabot, /dependency-name:\s*node/); +}); + test('CI workflow runs lint before tests and build', () => { const workflow = read('.github/workflows/ci.yml'); @@ -69,6 +77,13 @@ test('CI validates Docker builds for pull requests without publishing images', ( assert.match(workflow, /push: false/); }); +test('dependabot auto-merge workflow updates stale branches before enabling auto-merge', () => { + const workflow = read('.github/workflows/dependabot-auto-merge.yml'); + + assert.match(workflow, /gh pr update-branch/); + assert.match(workflow, /mergeStateStatus/); +}); + test('Dockerfile is self-contained and no longer relies on curl-impersonate', () => { const dockerfile = read('Dockerfile');