Skip to content

Commit 3315330

Browse files
committed
Hardening auto-merge
1 parent 540ee3f commit 3315330

File tree

1 file changed

+7
-3
lines changed

1 file changed

+7
-3
lines changed

.github/workflows/dependabot_automerge.yml

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,16 @@
11
# from https://github.com/gofiber/swagger/blob/main/.github/workflows/dependabot_automerge.yml
22
name: Dependabot auto-merge
33
on:
4-
pull_request_target:
4+
pull_request:
5+
6+
permissions:
7+
contents: write
8+
pull-requests: write
59

610
jobs:
711
automerge:
812
runs-on: ubuntu-latest
9-
if: ${{ github.event.pull_request.user.login == 'dependabot[bot]' }}
13+
if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository == 'ruby/rake'
1014
steps:
1115
- name: Dependabot metadata
1216
uses: dependabot/fetch-metadata@v2
@@ -22,5 +26,5 @@ jobs:
2226
if: ${{ steps.metadata.outputs.update-type == 'version-update:semver-minor' || steps.metadata.outputs.update-type == 'version-update:semver-patch'}}
2327
run: gh pr merge --auto --merge "$PR_URL"
2428
env:
25-
PR_URL: ${{github.event.pull_request.html_url}}
29+
PR_URL: ${{ github.event.pull_request.html_url }}
2630
GITHUB_TOKEN: ${{ secrets.MATZBOT_GITHUB_TOKEN }}

0 commit comments

Comments
 (0)