Repository navigation
ci(update-prs): every update merges itself once CI is green (issue #10) - #120
Merged
Merged
Conversation
The owner's choice, 2026-10-01: Node majors, pnpm's next major, Dependabot's majors (tooling and shipped libraries), patched-library majors, fsaunpack, GitHub Actions, the actionlint and zizmor images and the upstream sync merge themselves, as minor and patch updates already did. The hold label still stops any of them. Each kind keeps or gains a check that holds it back when it is not what it should be: - only its bot's commits (the owner's merges of main too, made with their token); an upstream sync's commits must each exist in upstream's repository; - only the files its kind changes: .nvmrc; workflow and action files; the two Dockerfiles; fsaunpack's package.json and package-lock.json; for an upstream sync anything but .github/, with no conflict commit and no added file that main's history has (one this project deleted, Chromium or YouTube say); - the dependency review, now for Actions and Docker updates too; - every version the lockfile adds 7 days old, fsaunpack's npm lockfile read with jq; - the build unchanged for what must not ship. A shipped library's major comes on its own branch: it ships when its dependency-name is one of the patterns of main's shipped-minor-and-patch group, and CI then runs on main. GitHub Actions updates change workflow files, which GITHUB_TOKEN may not merge or update: update-prs uses the owner's fine-grained token, secret UPDATE_PRS_TOKEN, for those alone (docs/maintenance.md says how to make it); without it they wait, saying so. An upstream sync merges as a merge commit, keeping upstream's commits; everything else squashes. tests/workflows/update-prs-decide.test.sh: 354 checks (was 293), and each of the 23 new guards, undone, fails its own scenario. actionlint, zizmor, all workflow tests and the unit tests pass. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
GLM (glm-5.3-flash) reviewed this PR; each finding that held is fixed here, with a scenario that fails when the fix is undone: - gh pr view reads at most 100 files and 100 commits (measured on gh 2.101: nodejs/node#66163, 789 files and 217 commits, gave 100 of each). A bigger upstream sync could have hidden a .github/ change or a foreign commit past that. The pull request's own counts (REST) are compared now; more, or unreadable counts, and it waits. - The list of files an upstream sync adds was read through a process substitution, so a failed call gave the deleted-file check nothing and the sync merged. It goes through a file now: a failure stops the run. - An upstream sync's lockfile gets the 7-day age check, as Dependabot's does. - An expired or revoked UPDATE_PRS_TOKEN failed this workflow on every run with no word on the pull request. It is tried first now, and a broken one is a reason: renew it. - fsaunpack's lockfile check counted any packages entry with a version (an npm workspace folder would have looked like an unknown package); only node_modules/ entries now. - tests/unit/checkToolchain.test.mjs pins the layout update-prs.yml reads the shipped libraries from: one flow-style patterns line of quoted names, each a dependency of package.json (a block list made it fail, as meant). Checked and left: the dependency review runs on every pull request to main (Actions and Docker updates too). 372 checks pass (was 354). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Second part of making issue #10 closable. Your decision (2026-10-01): every update merges itself once CI is green, majors included. The
holdlabel still stops any PR.Now merges itself (before, it waited for you):
toolchain/node-*).nvmrc; the build is unchangedpackageManager. One that wants the lockfile rewritten fails CI and still waitsmainafterwards, like the shipped groupmainfsaunpack/package.jsonandfsaunpack/package-lock.json, and every version that lockfile adds is 7 days old (the npm lockfile is read with jq)--merge, keeping upstream's commits. Conditions: no conflict commit; nothing under.github/; no added file thatmain's history already has (something this fork deleted); every commit exists in Andrew's repositoryAnything that fails a check still waits for you with one comment naming the check. A shipped library's major is recognised by its
dependency-namematching theshipped-minor-and-patchpatterns inmain's.github/dependabot.yml. If that file can't be read, the update counts as tooling, whose build must not change, so it waits rather than merging untested.Your token for GitHub Actions updates: GitHub's own workflow token may not merge or update a branch that changes workflow files. So
update-prs.ymlusesUPDATE_PRS_TOKEN, a fine-grained token of yours limited to this repository (Contents, Pull requests, Workflows: read and write), and only for those PRs. It never runs the PR's code.docs/maintenance.md, "A token for workflow updates", has the clicks. Until the secret exists, those PRs wait and say so.Tests:
tests/workflows/update-prs-decide.test.sh: 354 checks, up from 293, with new scenarios for every kind above and each way it should wait.Independent review (GLM), fixed in 8afe5b7, each with a scenario that fails when the fix is undone:
gh pr viewreads at most 100 files and 100 commits (measured: a 789-file, 217-commit PR gave 100 of each). A big upstream sync could have hidden a.github/change or a foreign commit past the cap. Now the PR's real counts are compared, and a bigger PR waits.UPDATE_PRS_TOKENis detected up front, and the PR says to renew it, instead of failing every run.node_modules/entries count as packages.dependabot.ymllayout the shipped-library list is read from.Checked, no change needed: the dependency review runs on every PR to
main, Actions and Docker ones included. The policy point stands as you chose it: third-party actions and images now merge after 5 days, a passing dependency review and green CI. Test count: 372 checks.Docs: the
docs/maintenance.mdtable and its "What update-prs.yml checks" section,CLAUDE.md, and the comments independabot.yml,sync-upstream.ymlandtoolchain-updates.yml.Ships nothing.
🤖 Generated with Claude Code