Skip to content

fix(pr-report): a pure Dependabot manifest/lockfile bump is its own work report - #1261

Merged
gHashTag merged 1 commit into
mainfrom
fix/work-report-dependabot-bumps
Oct 2, 2026
Merged

gHashTag merged 1 commit into
mainfrom
fix/work-report-dependabot-bumps

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Dependabot PRs (#780, #778, #775) are blocked by the required T27 work report status because Dependabot never writes a report block. This makes a pure Dependabot dependency bump its own report, and keeps everything else strict.

Exempt only when all hold (from GitHub API data, never PR code): author dependabot[bot] (type Bot); head is a dependabot/ branch in this repo; every changed file is a manifest/lockfile basename (DEPENDENCY_FILE; workflow files excluded on purpose); file status modified/added; every commit authored by Dependabot, committer web-flow, signature verified; commit list ends at the head SHA; file/commit counts match the PR's. A body that has a report block is validated normally. The bump writes a kind: dependency-bump report.json (no tests claimed), no blog draft, no outbox issue.

Dry run with live data (same steps as the workflow): #780, #778, #775 -> rc 0, dependency bump; #1202 -> rc 1, missing block.

After merge, re-run PR work report and blog via workflow_dispatch with pr=780/778/775 to post the status on their current heads.

{
  "version": 1,
  "head_sha": "3127a781e4825f6906264e642e120d62a6ad3eb6",
  "summary": "The required T27 work report status now passes for a pure Dependabot bump that changes only dependency manifests and lockfiles, while humans and agents still need a full report block.",
  "changes": [
    "scripts/pr_blog_report.py gains dependency_bump_refusal and dependency_bump_report: author dependabot[bot] of type Bot, a dependabot/ branch in this repo, only manifest or lockfile basenames, and every commit authored by Dependabot and GitHub-signed via web-flow.",
    "pr-blog-report.yml fetches the PR's changed files and commits as JSON lines and passes them to the validator; the status description names a dependency bump.",
    "pr_blog_dispatch.py skips the blog outbox for a dependency-bump report, since no blog draft is produced for it.",
    "Nine new unit tests in scripts/test_pr_blog_report.py and a new section in docs/PR_BLOG_AUTOMATION.md describe the exemption and its limits."
  ],
  "tests": [
    {
      "command": "python3 -m unittest discover -s scripts -p 'test_pr_blog*.py'",
      "result": "Ran 54 tests locally, all passed, including the nine new dependency-bump cases.",
      "status": "passed",
      "evidence": "Local run on the PR head in a fresh /tmp clone: 'Ran 54 tests ... OK'."
    },
    {
      "command": "pr_blog_report.py validate with live API data for PRs 780, 778, 775 and 1202, built exactly as the workflow builds it",
      "result": "780, 778 and 775 were accepted as dependency bumps; 1202 still failed for its missing report block.",
      "status": "passed",
      "evidence": "Local dry run: rc=0 for the three Dependabot PRs, rc=1 for 1202 with 'PR body must contain exactly one' block."
    }
  ],
  "limitations": [
    "The workflow change itself runs from main under pull_request_target, so the real status on Dependabot PRs is only observable after merge and a re-run of the report workflow for each PR.",
    "Dependabot bumps of GitHub Actions workflow files are deliberately not exempt and still need a human-written report."
  ],
  "tags": [
    "CI",
    "Dependabot",
    "WorkReport"
  ],
  "blog": {
    "title": "A dependency bump is its own work report",
    "summary": "The mandatory work report blocked every Dependabot PR; a narrow, signature-checked exemption lets pure manifest and lockfile bumps through while keeping people and agents strict.",
    "outline": [
      "The repository requires a T27 work report status on every PR, and Dependabot never writes the JSON block, so every dependency bump sat blocked regardless of its CI results.",
      "The validator now reads the changed files and commits from the GitHub API and accepts a missing block only when every file is a manifest or lockfile and every commit is Dependabot's own signed commit.",
      "A human push to a Dependabot branch, a workflow file bump, or any source file change ends the exemption, and a body that carries a report block is always validated normally."
    ]
  }
}

🤖 Generated with Claude Code

…ork report

The required "T27 work report" status blocked every Dependabot PR (#780, #778,
#775): Dependabot never writes a report block. The validator now accepts a
PR with no report block only when the author is dependabot[bot], the branch
is a dependabot/ branch in this repo, every changed file is a dependency
manifest or lockfile, and every commit is Dependabot's own GitHub-signed
commit. The workflow passes the changed files and commits as data; the bump
is recorded as a dependency-bump report.json, no blog draft, no publication
task. Humans and agents stay strict; a body with a report block is always
validated normally.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions github-actions Bot added the status:in-progress 🔵 Agent working label Oct 2, 2026
@gHashTag gHashTag added the bee-reviewed A reviewer bee reviewed and verified this PR after its head commit; required to merge label Oct 2, 2026
@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Bee review: evidence for #1261 at 3127a781e4825f6906264e642e120d62a6ad3eb6

Read the full diff (workflow, validator, dispatcher, tests, docs).

Gate analysis (security-relevant):

  • Author identity comes from pull_request.user.login == "dependabot[bot]" AND user.type == "Bot", which is GitHub API data. A display name is never consulted, so a human named "dependabot" gets nothing.
  • Forks are refused: head.repo.full_name must equal base.repo.full_name, and the head ref must start with dependabot/.
  • Workflow files are refused because the basename allowlist has no *.yml. Removed and renamed files are refused too (the status must be modified, added or changed).
  • Human pushes are refused: every commit must have author.login == dependabot[bot], committer.login == web-flow, verification.verified == true, the list must end at the head SHA, and the file and commit counts must match the PR (fail-closed on truncation).
  • Workflow trust: the workflow stays pull_request_target with ref: main and persist-credentials: false, so the PR's own copy of the workflow and validator cannot run with the token. Files and commits are fetched from the API as data.
  • Report blocks: a body that carries a report block always takes the normal strict path.
  • Residual, by design (named, not blocking): an actor who already has write access could create an API or web commit (web-flow-signed) whose author email is Dependabot's on a dependabot/ branch and keep the exemption for a manifest/lockfile-only change. That actor already holds write access, and the exemption only waives the paperwork status, not the bee review of the diff. Bee review of lockfile bumps stays mandatory.

Tests (run locally on the PR head files): python3 -m unittest discover -s scripts -p 'test_pr_blog*.py' gives Ran 54 tests ... OK.

Live dry run with the workflow's exact data pipeline: #780 rc 0, #778 rc 0, #775 rc 0 (dependency bump, all commits dependabot[bot]/web-flow/verified). #1202 rc 0 through the normal report path (its body now carries a block).

Checks:

  • T27 work report is success.
  • pr-opened (Auto-update Project Status) fails with gh: Bad credentials (HTTP 401) in "Get project item ID". This is an expired project token, red on every recent PR and on main issue events. fix(pr-report): a pure Dependabot manifest/lockfile bump is its own work report #1261 did not cause it.
  • Documentation Consistency fails with src/hslm/tjepa.zig not found, the same failure as the latest main docs-check run. It is not caused by this PR.
  • Brain Health Check/Report are red on main (a stub).

Verdict: sound. Merging.

@t27-bees t27-bees Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

bee review: see evidence comment

@gHashTag
gHashTag merged commit b4bbb5c into main Oct 2, 2026
40 of 49 checks passed
@github-actions github-actions Bot added status:completed Done and removed status:in-progress 🔵 Agent working labels Oct 2, 2026
github-actions Bot added a commit that referenced this pull request Oct 2, 2026
fix(pr-report): a pure Dependabot manifest/lockfile bump is its own work report (#1261)

The required "T27 work report" status blocked every Dependabot PR (#780, #778,
#775): Dependabot never writes a report block. The validator now accepts a
PR with no report block only when the author is dependabot[bot], the branch
is a dependabot/ branch in this repo, every changed file is a dependency
manifest or lockfile, and every commit is Dependabot's own GitHub-signed
commit. The workflow passes the changed files and commits as data; the bump
is recorded as a dependency-bump report.json, no blog draft, no publication
task. Humans and agents stay strict; a body with a report block is always
validated normally.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bee-reviewed A reviewer bee reviewed and verified this PR after its head commit; required to merge status:completed Done

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant