Skip to content

ci: auto-merge GitHub Actions Dependabot updates#21

Merged
slegarraga merged 1 commit into
mainfrom
ci/auto-merge-actions
Jun 29, 2026
Merged

ci: auto-merge GitHub Actions Dependabot updates#21
slegarraga merged 1 commit into
mainfrom
ci/auto-merge-actions

Conversation

@slegarraga

Copy link
Copy Markdown
Owner

Extends the Dependabot auto-merge workflow to also auto-merge github-actions ecosystem updates at any semver level, still gated on required CI passing.

Action bumps (checkout, setup-node, codeql-action, scorecard, fetch-metadata) are CI-only and low risk, so routine major bumps like checkout v6 -> v7 can close themselves once CI is green. The major-review policy stays in place for npm package updates, which can affect consumers.

@slegarraga slegarraga merged commit ff7d940 into main Jun 29, 2026
5 checks passed
@slegarraga slegarraga deleted the ci/auto-merge-actions branch June 29, 2026 18:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant