Skip to content

Re-arm Dependabot PRs that GitHub silently disarmed - #18

Merged
soodoku merged 2 commits into
masterfrom
ci/rearm-stranded-dependabot-prs
Aug 8, 2026
Merged

Re-arm Dependabot PRs that GitHub silently disarmed#18
soodoku merged 2 commits into
masterfrom
ci/rearm-stranded-dependabot-prs

Conversation

@soodoku

@soodoku soodoku commented Aug 8, 2026

Copy link
Copy Markdown
Member

Nine green Dependabot PRs had accumulated on appeler/pranaam while every auto-merge run reported success. The cause, from run 30836798988 (PR #29):

17:27:09  eligible=true
17:27:11  gh pr merge --auto  -> succeeded            (armed)
17:42:32  required check `build` completes  success
17:42:33  job `deploy` completes            skipped
17:42:38  auto_merge_disabled                          <- GitHub, 4s later

Auto-merge was armed. GitHub disarmed it once a PR-triggered workflow finished with a skipped job, and on: pull_request never fires again — so nothing re-arms, ever. calibre and the others have not hit this only because they happen to have no skipped job in a PR-triggered workflow. The automation is green throughout.

What changed

A schedule: trigger (every 3h) that re-arms stranded PRs. It converges regardless of why GitHub disarmed, which a workflow_run trigger racing the disarm event would not.

Eligibility is still decided exactly once, by dependabot/fetch-metadata in the pull_request context where it is reliable — the verdict is recorded as an automerge-eligible label and read back by the sweep. Deriving it a second time from a branch name would not recover major-versus-minor, and two copies of the rule would drift.

The sweep reads statusCheckRollup, not mergeStateStatus alone: CLEAN is GitHub's opinion about mergeability, and this job needs the stronger fact that every check is terminal and none failed before it merges anything directly.

It logs a line per PR — armed / merged / ineligible / checks-failing / already-armed — and warns when an eligible PR it cannot act on has been open past STALE_AFTER_HOURS. A sweep that quietly does nothing would reproduce the bug it fixes.

Verified

Decision logic run against the five real open pranaam PRs and six fixtures:

901  merge  checks terminal and green        <- the stranded case this fixes
902  arm    checks still running
903  none   checks failing                   <- never merges a failing PR
904  none   already armed
905  none   not mergeable (BLOCKED)
32   none   ineligible (no policy label)     <- real PR, a Python major

The five real ones are Python-ecosystem majors and the sweep refuses all of them, which is the negative check.

🤖 Generated with Claude Code

Auto-merge is armed on PR open, then GitHub disables it when a PR-triggered
workflow completes with a skipped job. Nothing re-arms it and every run still
reports success, so green PRs accumulate. Measured on appeler/pranaam, where
nine had.

Adds a scheduled sweep that re-arms or lands stranded PRs and logs a line for
each one. Eligibility is still decided once, by fetch-metadata in the
pull_request context, and recorded as a label the sweep reads back.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e162f461d8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

- name: Record the verdict on the PR
if: steps.gate.outputs.eligible == 'true'
env:
PR_URL: ${{ github.event.pull_request.html_url }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Grant issues permission before managing repository labels

On every eligible PR, this command attempts to create or update a repository label, but the workflow's explicit permissions block omits issues: write; unspecified permissions are set to none. GitHub's Create a label endpoint requires Issues write permission, and gh label create --help confirms that --force updates an existing label too, so this fails even after the label exists. Because the shell exits on that failure, neither the label nor auto-merge is applied, and the sweep subsequently treats the PR as ineligible.

Useful? React with 👍 / 👎.

acted=$((acted + 1)) ;;
merge)
echo "merging #$n"
gh pr merge "$n" --squash --delete-branch || echo "::warning::could not merge #$n"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve push workflows when directly merging PRs

When the sweep sees terminal-green checks, this immediately merges using the repository GITHUB_TOKEN. GitHub does not create new workflow runs for events caused by GITHUB_TOKEN, so the resulting push to main will not start the push-only deployment path in .github/workflows/docs.yml (its deploy job is skipped for PR events). Consequently, dependencies or Actions affecting documentation can land without rebuilding/deploying the site; use a token whose events trigger workflows or explicitly dispatch the required post-merge workflows.

Useful? React with 👍 / 👎.

zizmor's excessive-permissions audit rejects a workflow-level write grant once
there is more than one job: it applies to every job whether or not that job
needs it. Both jobs here do need both scopes, but they now say so themselves.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@soodoku
soodoku merged commit b0c6ff5 into master Aug 8, 2026
12 checks passed
@soodoku
soodoku deleted the ci/rearm-stranded-dependabot-prs branch August 8, 2026 23:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant