Repository navigation
fix(pr-report): a pure Dependabot manifest/lockfile bump is its own work report - #1261
Merged
Merged
Conversation
…ork report The required "T27 work report" status blocked every Dependabot PR (#780, #778, #775): Dependabot never writes a report block. The validator now accepts a PR with no report block only when the author is dependabot[bot], the branch is a dependabot/ branch in this repo, every changed file is a dependency manifest or lockfile, and every commit is Dependabot's own GitHub-signed commit. The workflow passes the changed files and commits as data; the bump is recorded as a dependency-bump report.json, no blog draft, no publication task. Humans and agents stay strict; a body with a report block is always validated normally. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Owner
Author
|
Bee review: evidence for #1261 at Read the full diff (workflow, validator, dispatcher, tests, docs). Gate analysis (security-relevant):
Tests (run locally on the PR head files): Live dry run with the workflow's exact data pipeline: #780 rc 0, #778 rc 0, #775 rc 0 (dependency bump, all commits Checks:
Verdict: sound. Merging. |
github-actions Bot
added a commit
that referenced
this pull request
Oct 2, 2026
fix(pr-report): a pure Dependabot manifest/lockfile bump is its own work report (#1261) The required "T27 work report" status blocked every Dependabot PR (#780, #778, #775): Dependabot never writes a report block. The validator now accepts a PR with no report block only when the author is dependabot[bot], the branch is a dependabot/ branch in this repo, every changed file is a dependency manifest or lockfile, and every commit is Dependabot's own GitHub-signed commit. The workflow passes the changed files and commits as data; the bump is recorded as a dependency-bump report.json, no blog draft, no publication task. Humans and agents stay strict; a body with a report block is always validated normally. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Dependabot PRs (#780, #778, #775) are blocked by the required T27 work report status because Dependabot never writes a report block. This makes a pure Dependabot dependency bump its own report, and keeps everything else strict.
Exempt only when all hold (from GitHub API data, never PR code): author
dependabot[bot](type Bot); head is adependabot/branch in this repo; every changed file is a manifest/lockfile basename (DEPENDENCY_FILE; workflow files excluded on purpose); file status modified/added; every commit authored by Dependabot, committerweb-flow, signature verified; commit list ends at the head SHA; file/commit counts match the PR's. A body that has a report block is validated normally. The bump writes akind: dependency-bumpreport.json(no tests claimed), no blog draft, no outbox issue.Dry run with live data (same steps as the workflow): #780, #778, #775 -> rc 0, dependency bump; #1202 -> rc 1, missing block.
After merge, re-run
PR work report and blogvia workflow_dispatch withpr=780/778/775to post the status on their current heads.{ "version": 1, "head_sha": "3127a781e4825f6906264e642e120d62a6ad3eb6", "summary": "The required T27 work report status now passes for a pure Dependabot bump that changes only dependency manifests and lockfiles, while humans and agents still need a full report block.", "changes": [ "scripts/pr_blog_report.py gains dependency_bump_refusal and dependency_bump_report: author dependabot[bot] of type Bot, a dependabot/ branch in this repo, only manifest or lockfile basenames, and every commit authored by Dependabot and GitHub-signed via web-flow.", "pr-blog-report.yml fetches the PR's changed files and commits as JSON lines and passes them to the validator; the status description names a dependency bump.", "pr_blog_dispatch.py skips the blog outbox for a dependency-bump report, since no blog draft is produced for it.", "Nine new unit tests in scripts/test_pr_blog_report.py and a new section in docs/PR_BLOG_AUTOMATION.md describe the exemption and its limits." ], "tests": [ { "command": "python3 -m unittest discover -s scripts -p 'test_pr_blog*.py'", "result": "Ran 54 tests locally, all passed, including the nine new dependency-bump cases.", "status": "passed", "evidence": "Local run on the PR head in a fresh /tmp clone: 'Ran 54 tests ... OK'." }, { "command": "pr_blog_report.py validate with live API data for PRs 780, 778, 775 and 1202, built exactly as the workflow builds it", "result": "780, 778 and 775 were accepted as dependency bumps; 1202 still failed for its missing report block.", "status": "passed", "evidence": "Local dry run: rc=0 for the three Dependabot PRs, rc=1 for 1202 with 'PR body must contain exactly one' block." } ], "limitations": [ "The workflow change itself runs from main under pull_request_target, so the real status on Dependabot PRs is only observable after merge and a re-run of the report workflow for each PR.", "Dependabot bumps of GitHub Actions workflow files are deliberately not exempt and still need a human-written report." ], "tags": [ "CI", "Dependabot", "WorkReport" ], "blog": { "title": "A dependency bump is its own work report", "summary": "The mandatory work report blocked every Dependabot PR; a narrow, signature-checked exemption lets pure manifest and lockfile bumps through while keeping people and agents strict.", "outline": [ "The repository requires a T27 work report status on every PR, and Dependabot never writes the JSON block, so every dependency bump sat blocked regardless of its CI results.", "The validator now reads the changed files and commits from the GitHub API and accepts a missing block only when every file is a manifest or lockfile and every commit is Dependabot's own signed commit.", "A human push to a Dependabot branch, a workflow file bump, or any source file change ends the exemption, and a body that carries a report block is always validated normally." ] } }🤖 Generated with Claude Code