Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 56 additions & 0 deletions .github/workflows/dependabot_review_request_cleanup.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
name: Dismiss Dependabot Review Request

"on":
pull_request_target:
types: [review_requested]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Use a review-request event that GitHub emits

pull_request_target does not emit the review_requested activity type (its supported activities are limited to assigned/unassigned, labeled/unlabeled, opened, synchronize, reopened, and closed). Consequently this workflow will never start when CODEOWNERS requests Pigbibi's review, so the requested review remains in place for every Dependabot PR.

Useful? React with 👍 / 👎.


permissions:
contents: read
issues: read
pull-requests: write

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number }}
cancel-in-progress: false

jobs:
dismiss-review-request:
if: >-
(github.event.pull_request.user.login == 'dependabot[bot]' ||
github.event.pull_request.user.login == 'app/dependabot') &&
github.event.requested_reviewer.login == 'Pigbibi' &&
(github.actor == 'dependabot[bot]' || github.actor == 'app/dependabot')
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Dismiss Pigbibi review request
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_NUMBER: ${{ github.event.pull_request.number }}
REVIEWER: Pigbibi
run: |
set -euo pipefail
review_requests="$(gh pr view "${PR_NUMBER}" \
--repo "${GITHUB_REPOSITORY}" \
--json reviewRequests \
--jq '.reviewRequests[].login')"
if ! grep -Fqx "${REVIEWER}" <<<"${review_requests}"; then
echo "No review request for ${REVIEWER}; nothing to dismiss." >> "${GITHUB_STEP_SUMMARY}"
exit 0
fi

latest_request_actor="$(gh api \
"repos/${GITHUB_REPOSITORY}/issues/${PR_NUMBER}/timeline?per_page=100" \
--jq '[.[] | select(.event == "review_requested" and .requested_reviewer.login == "Pigbibi")][-1].actor.login // ""')"
case "${latest_request_actor}" in
'dependabot[bot]'|'app/dependabot') ;;
*)
echo "Latest review request was made by ${latest_request_actor:-<unknown>}; preserving it." >> "${GITHUB_STEP_SUMMARY}"
exit 0
;;
esac

gh api --method DELETE \
"repos/${GITHUB_REPOSITORY}/pulls/${PR_NUMBER}/requested_reviewers" \
-f "reviewers[]=${REVIEWER}"
Comment thread
Pigbibi marked this conversation as resolved.
echo "Dismissed Dependabot review request for ${REVIEWER}." >> "${GITHUB_STEP_SUMMARY}"
Loading