Non-Blocking Review Concern: trusted_namespaces omits 'dependabot' and 'actions' that were in the inline allowlist
Source: pre-push whole-codebase review
Location: .github/workflows/dependabot-auto-merge.yml:15
Date: 2026-08-11
What was flagged
The removed inline logic treated dependabot/, actions/, and smartwatermelon/ as trusted namespaces for major-bump auto-merge. The replacement only passes trusted_namespaces: 'smartwatermelon'. If the reusable workflow does not have dependabot/ and actions/ as hardcoded defaults, major-version bumps from those namespaces will now require manual review where they previously auto-merged. This may be intentional tightening of policy — but it should be verified against the reusable workflow's behavior to confirm it's not an accidental regression. Worth confirming with smartwatermelon/github-workflows that those namespaces are either baked in as defaults or not needed.
Context
This issue was automatically created from a non-blocking concern identified
during pre-push whole-codebase review. It was flagged for tracking.
Created by lib-review-issues.sh
Non-Blocking Review Concern: trusted_namespaces omits 'dependabot' and 'actions' that were in the inline allowlist
Source: pre-push whole-codebase review
Location:
.github/workflows/dependabot-auto-merge.yml:15Date: 2026-08-11
What was flagged
The removed inline logic treated
dependabot/,actions/, andsmartwatermelon/as trusted namespaces for major-bump auto-merge. The replacement only passestrusted_namespaces: 'smartwatermelon'. If the reusable workflow does not havedependabot/andactions/as hardcoded defaults, major-version bumps from those namespaces will now require manual review where they previously auto-merged. This may be intentional tightening of policy — but it should be verified against the reusable workflow's behavior to confirm it's not an accidental regression. Worth confirming withsmartwatermelon/github-workflowsthat those namespaces are either baked in as defaults or not needed.Context
This issue was automatically created from a non-blocking concern identified
during pre-push whole-codebase review. It was flagged for tracking.
Created by lib-review-issues.sh