Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 56 additions & 0 deletions .github/workflows/dependabot_review_request_cleanup.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
name: Dismiss Dependabot Review Request

"on":
pull_request_target:
types: [review_requested]

permissions:
contents: read
issues: read
pull-requests: write

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number }}
cancel-in-progress: false

jobs:
dismiss-review-request:
if: >-
(github.event.pull_request.user.login == 'dependabot[bot]' ||
github.event.pull_request.user.login == 'app/dependabot') &&
github.event.requested_reviewer.login == 'Pigbibi' &&
(github.actor == 'dependabot[bot]' || github.actor == 'app/dependabot')
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Dismiss Pigbibi review request
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_NUMBER: ${{ github.event.pull_request.number }}
REVIEWER: Pigbibi
run: |
set -euo pipefail
review_requests="$(gh pr view "${PR_NUMBER}" \
--repo "${GITHUB_REPOSITORY}" \
--json reviewRequests \
--jq '.reviewRequests[].login')"
if ! grep -Fqx "${REVIEWER}" <<<"${review_requests}"; then
echo "No review request for ${REVIEWER}; nothing to dismiss." >> "${GITHUB_STEP_SUMMARY}"
exit 0
fi

latest_request_actor="$(gh api \
"repos/${GITHUB_REPOSITORY}/issues/${PR_NUMBER}/timeline?per_page=100" \
--jq '[.[] | select(.event == "review_requested" and .requested_reviewer.login == "Pigbibi")][-1].actor.login // ""')"
Comment on lines +42 to +44

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Paginate timeline events before choosing the latest request

For a Dependabot PR with more than 100 timeline events, this only inspects the first API page, so [-1] need not be the latest Pigbibi request. If Dependabot made the original request in that page and a maintainer re-requested review later, the job identifies the old Dependabot actor and deletes the currently pending manual request, defeating the preservation check. Fetch all pages (or otherwise query the newest matching event) before deciding to remove it.

Useful? React with 👍 / 👎.

case "${latest_request_actor}" in
'dependabot[bot]'|'app/dependabot') ;;
*)
echo "Latest review request was made by ${latest_request_actor:-<unknown>}; preserving it." >> "${GITHUB_STEP_SUMMARY}"
exit 0
;;
esac

gh api --method DELETE \
"repos/${GITHUB_REPOSITORY}/pulls/${PR_NUMBER}/requested_reviewers" \
-f "reviewers[]=${REVIEWER}"
Comment thread
Pigbibi marked this conversation as resolved.
echo "Dismissed Dependabot review request for ${REVIEWER}." >> "${GITHUB_STEP_SUMMARY}"
Loading