Repository navigation
ci: stop auto-approving and auto-merging Dependabot PRs - #28
Merged
Merged
Conversation
Dependabot PRs are now reviewed and merged manually, so the projen auto-approve workflow, its auto-merge overrides, and the auto-approve Dependabot label are no longer needed.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Dependabot PRs now wait for a manual review and merge instead of being approved and merged automatically.
Before this change, projen's
auto_approve_optionsgenerated.github/workflows/auto-approve.yml. That workflow ran onpull_request_targetfor any Dependabot PR labeledauto-approve, approved it withGITHUB_TOKEN, and then turned on auto-merge usingPROJEN_GITHUB_TOKEN. Dependabot added that label to every uv update it opened.This PR removes
auto_approve_optionsand the overrides that added the checkout and auto-merge steps. It also stops Dependabot from applying theauto-approvelabel (thedependencieslabel stays). Runninguv run projendeleted the workflow and removed its entries from.gitattributes,.gitignoreand.projen/files.json. Two comments that listed auto-approve as a projen-managed workflow now list only pull-request-lint.Validation
Local runs on this branch:
uv run projen: the workflow was deleted and the generated files were updated without errorsuv run ruff checkandruff format --checkon.projenrc.pyandsrc/bin/cicd_helper.py: passeduv run projen test: 1 passeduv run projen validate: "Validation did not find any problems."ruff check .across the whole repo still reports 2 import-order errors insrc/app.pyandsrc/stacks/github_oidc_stack.py. Those errors were already onmainand this PR doesn't touch those files.After merge
PROJEN_GITHUB_TOKENrepository secret anymore, so it can be deleted unless something outside this repo uses it.auto-approvelabel can be deleted from the repository.