Skip to content

Commit 668eb5d

Browse files
committed
ci(dependencies): automate dependencies updates
Signed-off-by: Frederic BIDON <[email protected]>
1 parent 91d0edd commit 668eb5d

File tree

3 files changed

+104
-4
lines changed

3 files changed

+104
-4
lines changed

.github/dependabot.yaml

+57
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,57 @@
1+
version: 2
2+
updates:
3+
- package-ecosystem: "github-actions"
4+
directory: "/"
5+
schedule:
6+
interval: "weekly"
7+
day: "friday"
8+
open-pull-requests-limit: 2 # <- default is 5
9+
groups: # <- group all github actions updates in a single PR
10+
# 1. development-dependencies are auto-merged
11+
development-dependencies:
12+
dependency-type: development
13+
patterns:
14+
- '*'
15+
16+
- package-ecosystem: "gomod"
17+
# We define 4 groups of dependencies to regroup update pull requests:
18+
# - development (e.g. test dependencies)
19+
# - go-openapi updates
20+
# - golang.org (e.g. golang.org/x/... packages)
21+
# - other dependencies (direct or indirect)
22+
#
23+
# * All groups are checked once a week and each produce at most 1 PR.
24+
# * All dependabot PRs are auto-approved
25+
#
26+
# Auto-merging policy, when requirements are met:
27+
# 1. development-dependencies are auto-merged
28+
# 2. golang.org-dependencies are auto-merged
29+
# 3. go-openapi patch updates are auto-merged. Minor/major version updates require a manual merge.
30+
# 4. other dependencies require a manual merge
31+
directory: "/"
32+
schedule:
33+
interval: "weekly"
34+
day: "friday"
35+
open-pull-requests-limit: 4
36+
groups:
37+
development-dependencies:
38+
dependency-type: development
39+
patterns:
40+
- "github.com/stretchr/testify"
41+
42+
golang.org-dependencies:
43+
dependency-type: production
44+
patterns:
45+
- "golang.org/*"
46+
47+
go-openapi-dependencies:
48+
dependency-type: production
49+
patterns:
50+
- "github.com/go-openapi/*"
51+
52+
other-dependencies:
53+
dependency-type: production
54+
exclude-patterns:
55+
- "github.com/go-openapi/*"
56+
- "github.com/stretchr/testify"
57+
- "golang.org/*"

.github/workflows/auto-merge.yml

+43
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
1+
name: Dependabot auto-merge
2+
on: pull_request
3+
4+
permissions:
5+
contents: write
6+
pull-requests: write
7+
8+
jobs:
9+
dependabot:
10+
runs-on: ubuntu-latest
11+
if: github.actor == 'dependabot[bot]'
12+
steps:
13+
- name: Dependabot metadata
14+
id: metadata
15+
uses: dependabot/fetch-metadata@v1
16+
17+
- name: Auto-approve all dependabot PRs
18+
run: gh pr review --approve "$PR_URL"
19+
env:
20+
PR_URL: ${{github.event.pull_request.html_url}}
21+
GH_TOKEN: ${{secrets.GITHUB_TOKEN}}
22+
23+
- name: Auto-merge dependabot PRs for development dependencies
24+
if: contains(steps.metadata.outputs.dependency-group, 'development-dependencies')
25+
run: gh pr merge --auto --rebase "$PR_URL"
26+
env:
27+
PR_URL: ${{github.event.pull_request.html_url}}
28+
GH_TOKEN: ${{secrets.GITHUB_TOKEN}}
29+
30+
- name: Auto-merge dependabot PRs for go-openapi patches
31+
if: contains(steps.metadata.outputs.dependency-group, 'go-openapi-dependencies') && (steps.metadata.outputs.update-type == 'version-update:semver-minor' || steps.metadata.outputs.update-type == 'version-update:semver-patch')
32+
run: gh pr merge --auto --rebase "$PR_URL"
33+
env:
34+
PR_URL: ${{github.event.pull_request.html_url}}
35+
GH_TOKEN: ${{secrets.GITHUB_TOKEN}}
36+
37+
- name: Auto-merge dependabot PRs for golang.org updates
38+
if: contains(steps.metadata.outputs.dependency-group, 'golang.org-dependencies')
39+
run: gh pr merge --auto --rebase "$PR_URL"
40+
env:
41+
PR_URL: ${{github.event.pull_request.html_url}}
42+
GH_TOKEN: ${{secrets.GITHUB_TOKEN}}
43+

.github/workflows/go-test.yml

+4-4
Original file line numberDiff line numberDiff line change
@@ -7,8 +7,8 @@ jobs:
77
name: Lint
88
runs-on: ubuntu-latest
99
steps:
10-
- uses: actions/checkout@v3
11-
- uses: actions/setup-go@v4
10+
- uses: actions/checkout@v4
11+
- uses: actions/setup-go@v5
1212
with:
1313
go-version: stable
1414
check-latest: true
@@ -31,13 +31,13 @@ jobs:
3131

3232
steps:
3333
- name: Run unit tests
34-
uses: actions/setup-go@v4
34+
uses: actions/setup-go@v5
3535
with:
3636
go-version: '${{ matrix.go_version }}'
3737
check-latest: true
3838
cache: true
3939

40-
- uses: actions/checkout@v3
40+
- uses: actions/checkout@v4
4141

4242
- run: go test -v -race -coverprofile="coverage-${{ matrix.os }}.${{ matrix.go_version }}.out" -covermode=atomic -coverpkg=$(go list)/... ./...
4343

0 commit comments

Comments
 (0)