Skip to content

ci: stop auto-approving and auto-merging Dependabot PRs - #28

Merged
dannysteenman merged 1 commit into
mainfrom
ci/remove-auto-approve
Oct 5, 2026
Merged

dannysteenman merged 1 commit into
mainfrom
ci/remove-auto-approve

Conversation

@dannysteenman

Copy link
Copy Markdown
Member

Dependabot PRs now wait for a manual review and merge instead of being approved and merged automatically.

Before this change, projen's auto_approve_options generated .github/workflows/auto-approve.yml. That workflow ran on pull_request_target for any Dependabot PR labeled auto-approve, approved it with GITHUB_TOKEN, and then turned on auto-merge using PROJEN_GITHUB_TOKEN. Dependabot added that label to every uv update it opened.

This PR removes auto_approve_options and the overrides that added the checkout and auto-merge steps. It also stops Dependabot from applying the auto-approve label (the dependencies label stays). Running uv run projen deleted the workflow and removed its entries from .gitattributes, .gitignore and .projen/files.json. Two comments that listed auto-approve as a projen-managed workflow now list only pull-request-lint.

Validation

Local runs on this branch:

  • uv run projen: the workflow was deleted and the generated files were updated without errors
  • uv run ruff check and ruff format --check on .projenrc.py and src/bin/cicd_helper.py: passed
  • uv run projen test: 1 passed
  • uv run projen validate: "Validation did not find any problems."

ruff check . across the whole repo still reports 2 import-order errors in src/app.py and src/stacks/github_oidc_stack.py. Those errors were already on main and this PR doesn't touch those files.

After merge

  • Nothing in the repo references the PROJEN_GITHUB_TOKEN repository secret anymore, so it can be deleted unless something outside this repo uses it.
  • The auto-approve label can be deleted from the repository.

Dependabot PRs are now reviewed and merged manually, so the projen
auto-approve workflow, its auto-merge overrides, and the auto-approve
Dependabot label are no longer needed.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-05T10:11:37.527751Z e21801d PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@dannysteenman dannysteenman added the impact:limited Localized, backward-compatible change label Oct 5, 2026
@dannysteenman
dannysteenman merged commit 741b52b into main Oct 5, 2026
5 checks passed
@dannysteenman
dannysteenman deleted the ci/remove-auto-approve branch October 5, 2026 10:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

impact:limited Localized, backward-compatible change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant