name: Dependabot Auto Merge on: pull_request_target: types: - opened - reopened - synchronize - ready_for_review permissions: contents: write pull-requests: write jobs: auto-merge: if: github.event.pull_request.user.login == 'dependabot[bot]' && !github.event.pull_request.draft runs-on: ubuntu-latest steps: - name: Approve the Dependabot pull request env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} PR_URL: ${{ github.event.pull_request.html_url }} run: gh pr review --repo "$GITHUB_REPOSITORY" "$PR_URL" --approve --body "Approved automatically after policy checks." || true - name: Enable auto-merge after required checks pass env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} PR_URL: ${{ github.event.pull_request.html_url }} run: gh pr merge --repo "$GITHUB_REPOSITORY" "$PR_URL" --auto --squash --delete-branch