Skip to content

ci: add dependabot auto-merge and pin actions to SHAs - #8

Merged
timonviola merged 1 commit into
mainfrom
ci/dependabot-auto-merge
Oct 1, 2026
Merged

timonviola merged 1 commit into
mainfrom
ci/dependabot-auto-merge

Conversation

@timonviola

Copy link
Copy Markdown
Contributor

Sets up automated Dependabot updates for this repo, following SneaksAndData/arcane-stream-sqlserver@17ef950.

Changes

  • .github/dependabot.yml: uses the grouped github-actions config (7-day cooldown, ci commit prefix, dependencies/github_actions labels, separate groups for version and security updates).
  • .github/workflows/dependabot-auto-merge.yaml (new): approves Dependabot PRs and enables auto-merge (squash). Major version bumps are excluded, except for GitHub Actions.
  • Validate commit (build.yaml): the job gets id-token: write, pull-requests: write and contents: read, which Dependabot PRs need. The workflow now sets permissions: {} at the top.
  • zizmor (zizmor --fix=all, plus manual fixes):
    • All actions are pinned to commit SHAs, with a version comment on each. The pinned versions are the ones already in use.
    • persist-credentials: false is set on every actions/checkout step.
    • release.yaml now has permissions: {} at workflow level, and create_release gets contents: write.
    • The pull_request_target trigger is marked as intentionally allowed with a zizmor ignore. The workflow never checks out PR code and only runs for dependabot[bot].

Verification

  • zizmor . (online) reports no findings (1 ignored, 6 suppressed).
  • actionlint reports no findings.

Dependencies

  • SneaksAndData/terraform#8427 turns on the repository rulesets that let Dependabot bypass required reviews. The ruleset requires the Validate commit check.
  • Auto-merge also requires allow_auto_merge = true on this repo, which is currently false.

- dependabot.yml: weekly grouped github-actions updates with 7-day cooldown, ci commit prefix and dependencies/github_actions labels
- add dependabot-auto-merge.yaml workflow (approve + auto-merge Dependabot PRs)
- build.yaml: dependabot permissions on the `Validate commit` job, workflow-level `permissions: {}`
- release.yaml: workflow-level `permissions: {}`, `contents: write` on create_release
- pin all actions to commit SHAs and set `persist-credentials: false` on checkouts via zizmor

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@timonviola
timonviola requested a review from a team as a code owner September 29, 2026 13:38
@timonviola timonviola added the code/ci-cd CI/CD pipeline feature, bug or request label Sep 29, 2026
@timonviola
timonviola merged commit eebf20c into main Oct 1, 2026
1 check passed
@timonviola
timonviola deleted the ci/dependabot-auto-merge branch October 1, 2026 08:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

code/ci-cd CI/CD pipeline feature, bug or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants