Skip to content

ops(ci): dependabot auto-merge lands PRs with red/pending CI — main has no branch protection or ruleset, so --auto merges immediately #3311

Description

@Xore

Found during #3194 (OmniRoute docs/ops/BRANCH_PROTECTION_MAIN.md comparison).

Observed

  • gh api repos/Xore/APIARY/branches/main/protection → 404 Branch not protected; gh api repos/Xore/APIARY/rulesets → empty. main has no required status checks at all.
  • .github/workflows/dependabot-auto-merge.yml approves patch/minor updates and runs gh pr merge --auto --squash. With zero required checks, GitHub reports the PR mergeable immediately and the call merges on the spot instead of arming a wait.
  • Dependabot PRs merged by github-actions[bot] 25–40 s after their CI started, with failures on their own head commits:
PR Merged Failed checks on its head
#3285 backend-compatible group 2026-09-25 06:15 backend-service, dicompot
#3288 base64 0.22→0.23 06:17 backend-service, dicompot
#3287 rand 0.9→0.10 06:20 Dashboard backend-service (Rust)
#3289 sha2 0.10→0.11 06:22 Dashboard backend-service (Rust)
#3291 actions-compatible group 06:18 backend-service, dicompot, dns-honeypot, rdp-honeypot, endlessh-honeypot, agent-intrusion-worker

Timeline for #3289: CI runs created 06:22:28, merged 06:22:56.

Proposal

  1. Add a ruleset on main with required status checks. Required contexts must be checks that always report (aggregate jobs), not path-filtered ones that skip, or every non-matching PR blocks forever — needs a check inventory first.
  2. Until then: make the workflow refuse to merge when gh pr view --json mergeStateStatus is CLEAN with no required checks, i.e. never call gh pr merge without protection; comment instead.
  3. Treat Cargo 0.x minor bumps as major for auto-merge (dependency-type/update-type + previous-version starts with 0.), or exclude Cargo from auto-merge.
  4. Correct the docs/CI-CD.md Dependabot paragraph.

Refs #3194.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingopsDeployment, runners, observability, host accesssecuritySecurity hardening or a security defect

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions