From 3801f0d969ecafd35bab2baced8afe7568c35d60 Mon Sep 17 00:00:00 2001 From: Shane Engelman Date: Sat, 3 Oct 2026 04:40:07 -0700 Subject: [PATCH 1/5] ci(dependabot): group updates weekly and auto-merge minor and patch Individual dependabot PRs pile up faster than one engineer can review them and go stale until they conflict (bbot-enterprise#141). Every ecosystem now runs weekly against dev and opens at most two grouped PRs: one for minor and patch bumps, one for majors. A pull_request_target workflow enables auto-merge (squash) on the minor/patch group so it lands once required checks pass. Majors still need a human. --- .github/dependabot.yml | 34 ++++++++++++++++----- .github/workflows/dependabot-auto-merge.yml | 21 +++++++++++++ 2 files changed, 48 insertions(+), 7 deletions(-) create mode 100644 .github/workflows/dependabot-auto-merge.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 18e2537..f54c34a 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -2,15 +2,35 @@ version: 2 updates: - package-ecosystem: "pip" directory: "/" + target-branch: "dev" schedule: interval: "weekly" - target-branch: "dev" - open-pull-requests-limit: 10 - - package-ecosystem: github-actions - directory: / groups: - github-actions: + pip-minor-patch: + patterns: + - "*" + update-types: + - "minor" + - "patch" + pip-major: patterns: - - "*" # Group all Actions updates into a single larger pull request + - "*" + update-types: + - "major" + - package-ecosystem: "github-actions" + directory: "/" + target-branch: "dev" schedule: - interval: weekly + interval: "weekly" + groups: + github-actions-minor-patch: + patterns: + - "*" + update-types: + - "minor" + - "patch" + github-actions-major: + patterns: + - "*" + update-types: + - "major" diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml new file mode 100644 index 0000000..37b7e35 --- /dev/null +++ b/.github/workflows/dependabot-auto-merge.yml @@ -0,0 +1,21 @@ +name: dependabot auto-merge + +on: pull_request_target + +permissions: {} + +jobs: + auto-merge: + if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository_owner == 'blacklanternsecurity' + runs-on: ubuntu-24.04 + permissions: + contents: write + pull-requests: write + steps: + - id: metadata + uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 + - if: steps.metadata.outputs.update-type != 'version-update:semver-major' + run: gh pr merge --auto --squash "$PR_URL" + env: + PR_URL: ${{ github.event.pull_request.html_url }} + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} From 68e20a9cf4e1c0725eada012a1e9fdf34ea42b5f Mon Sep 17 00:00:00 2001 From: Shane Engelman Date: Sat, 3 Oct 2026 07:17:34 -0700 Subject: [PATCH 2/5] ci(dependabot): call the shared auto-merge workflow The auto-merge job was a byte-identical copy in ten repositories. It now calls dependabot-auto-merge.yml in blacklanternsecurity/.github, pinned by SHA, so the fetch-metadata pin and merge policy live in one place. The trigger moves from pull_request_target to pull_request. Dependabot branches live in this repository, so the privileged target context was never needed and zizmor flags it as a dangerous trigger. dependabot.yml moves from pip to uv to match the uv.lock migration in webcap#132. The pip ecosystem would stop updating the lockfile. --- .github/dependabot.yml | 6 +++--- .github/workflows/dependabot-auto-merge.yml | 16 +++------------- 2 files changed, 6 insertions(+), 16 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index f54c34a..b375c70 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,18 +1,18 @@ version: 2 updates: - - package-ecosystem: "pip" + - package-ecosystem: "uv" directory: "/" target-branch: "dev" schedule: interval: "weekly" groups: - pip-minor-patch: + uv-minor-patch: patterns: - "*" update-types: - "minor" - "patch" - pip-major: + uv-major: patterns: - "*" update-types: diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index 37b7e35..9d8088b 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -1,21 +1,11 @@ -name: dependabot auto-merge - -on: pull_request_target +name: Dependabot auto-merge +on: pull_request permissions: {} jobs: auto-merge: - if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository_owner == 'blacklanternsecurity' - runs-on: ubuntu-24.04 permissions: contents: write pull-requests: write - steps: - - id: metadata - uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 - - if: steps.metadata.outputs.update-type != 'version-update:semver-major' - run: gh pr merge --auto --squash "$PR_URL" - env: - PR_URL: ${{ github.event.pull_request.html_url }} - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + uses: blacklanternsecurity/.github/.github/workflows/dependabot-auto-merge.yml@b51d74d4611e27f2a452472e0f9ef12e8926d41c # 2026-10-03 From e54ef61434c0e2d7997bbe0327ef760282735875 Mon Sep 17 00:00:00 2001 From: Shane Engelman Date: Sat, 3 Oct 2026 07:27:04 -0700 Subject: [PATCH 3/5] ci(dependabot): call auto-merge from the public CLA repository blacklanternsecurity/.github is private, so public repositories cannot call reusable workflows from it and the run failed as a workflow file issue. The shared workflow lives in blacklanternsecurity/CLA, which is public and already hosts cla-reusable.yml. --- .github/workflows/dependabot-auto-merge.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index 9d8088b..dbec312 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -8,4 +8,4 @@ jobs: permissions: contents: write pull-requests: write - uses: blacklanternsecurity/.github/.github/workflows/dependabot-auto-merge.yml@b51d74d4611e27f2a452472e0f9ef12e8926d41c # 2026-10-03 + uses: blacklanternsecurity/CLA/.github/workflows/dependabot-auto-merge.yml@0654fbb8b305e452219b14480d31ff56efc74b73 # 2026-10-03 From 8463f6f9da76f471b6c5e744a77bf60799d8eb79 Mon Sep 17 00:00:00 2001 From: Shane Engelman Date: Sat, 3 Oct 2026 07:42:42 -0700 Subject: [PATCH 4/5] ci(dependabot): gate auto-merge on finished checks dev carries no required checks (#139), so gh pr merge --auto would merge immediately rather than on green. The shared workflow now waits for every other check on the head commit, refuses on failure or cancel, and merges with --match-head-commit. The caller grants checks: read so it can read check state. --- .github/workflows/dependabot-auto-merge.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index dbec312..f70c63e 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -8,4 +8,5 @@ jobs: permissions: contents: write pull-requests: write - uses: blacklanternsecurity/CLA/.github/workflows/dependabot-auto-merge.yml@0654fbb8b305e452219b14480d31ff56efc74b73 # 2026-10-03 + checks: read + uses: blacklanternsecurity/CLA/.github/workflows/dependabot-auto-merge.yml@bd5493d26aab101458d606886d23e62b1354cdba # 2026-10-03 From 5d64b0a22e5e7b746ce1143577efb0587fcc01f1 Mon Sep 17 00:00:00 2001 From: Shane Engelman Date: Sat, 3 Oct 2026 07:43:50 -0700 Subject: [PATCH 5/5] ci(dependabot): pin the shared workflow to the current CLA tip Aligns with the SHA the other shared CLA workflows are pinned to. The auto-merge workflow is unchanged between the two commits. --- .github/workflows/dependabot-auto-merge.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index f70c63e..1730bc4 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -9,4 +9,4 @@ jobs: contents: write pull-requests: write checks: read - uses: blacklanternsecurity/CLA/.github/workflows/dependabot-auto-merge.yml@bd5493d26aab101458d606886d23e62b1354cdba # 2026-10-03 + uses: blacklanternsecurity/CLA/.github/workflows/dependabot-auto-merge.yml@e532142ee9e7322888f6edc80d9a89e2f8c0d96d # 2026-10-03