From be1dd73f6de8e31037b233f996cc94f1d63e5661 Mon Sep 17 00:00:00 2001 From: Carlos Alexandro Becker Date: Fri, 1 Nov 2024 10:41:12 -0300 Subject: [PATCH] feat: dependabot auto-merge --- .github/workflows/build.yml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 5f54bba..b605aa3 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -68,3 +68,21 @@ jobs: - name: Test run: go test ./... working-directory: ${{ inputs.working-directory }} + dependabot: + needs: [test, govulncheck] + runs-on: ubuntu-latest + permissions: + pull-requests: write + contents: write + if: ${{ github.actor == 'dependabot[bot]' && github.event_name == 'pull_request'}} + steps: + - id: metadata + uses: dependabot/fetch-metadata@dbb049abf0d677abbd7f7eee0375145b417fdd34 # v2.2.0 + with: + github-token: "${{ secrets.GITHUB_TOKEN }}" + - run: | + gh pr review --approve "$PR_URL" + gh pr merge --squash "$PR_URL" + env: + PR_URL: ${{github.event.pull_request.html_url}} + GITHUB_TOKEN: ${{secrets.gh_pat}}