Home

dev / openkara

publicthedavidweng/OpenKara· sync paused
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

ci: align dependabot automerge contract tests with current workflow

merged
#461 opened by devci/fix-dependabot-automerge-contract→main
Conversation3 Commits0
devopened this pull requestAuthor· last week
Files changed
…

Summary

  • .github/workflows/dependabot-automerge.yml was rewritten to the current pull_request_target policy (empty top-level permissions, job-scoped contents/pull-requests write, security/patch/actions eligibility, release-tooling denylist), but tests/ci/dependabot-automerge-contract.test.ts still encoded the pre-rewrite contract.
  • That stale contract failed App frontend build / test on main and every Dependabot PR. tauri-build-smoke then skipped via needs.app-frontend.result != 'failure', and CI Gate failed both jobs.
  • Update the contract tests to assert the actual security model that is implemented — no CI weakening, no skipped checks.

Root cause (failing assertions on main)

  1. auto-merge is limited to semver patch and minor — test forbade any third version-update:semver-* string; workflow correctly uses semver-major as an exclusion for github-actions bumps.
  2. denylists native audio... crates — test expected a crate DENYLIST:; workflow denylists googleapis/release-please-action / dependabot/fetch-metadata.
  3. keeps top-level permissions read-only — test expected contents: read; workflow intentionally uses permissions: {} + job-scoped write.

Verification

  • Local: CI=true node --run test -- --coverage → 212 files / 2371 tests passed; coverage above thresholds (83.5/76.6/79.5/84.4 vs 65/60/60/60).
  • Pre-push lefthook: lint, format, knip, standards-route, patch-coverage all green.

Updates the Dependabot auto-merge contract tests to match the current workflow.

The tests now verify:

  • pull_request_target security behavior.
  • Empty top-level permissions.
  • Job-scoped contents and pull-requests write permissions.
  • Same-repository Dependabot heads.
  • No pull-request checkout.
  • Eligibility for security, patch, non-production minor, and non-major github-actions updates.
  • Denylists for release-please-action and fetch-metadata.
  • Removal of obsolete native crate denylist assertions.
coderabbitai[bot]commented· last week

Review Change StackReview Change Stack

[!NOTE] Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: thedavidweng/OpenKara/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 610e573c-1f01-45b6-805e-e1d743597993

📥 Commits

Reviewing files that changed from the base of the PR and between 81460e9c904fdedf5be3ccfaec8afcc1ae1f4929 and 3099a0f288e178aa699a140ed02cc37dc99f2035.

📒 Files selected for processing (1)
  • tests/ci/dependabot-automerge-contract.test.ts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
  • X
  • Mastodon
  • Reddit
  • LinkedIn

Comment [@coderabbitai](/coderabbitai) help to get the list of available commands.

github-actions[bot]commented· last week

Coverage Report

Status Category Percentage Covered / Total
🟢 Lines 84.39% (🎯 65%) 7626 / 9036
🟢 Statements 83.54% (🎯 65%) 8080 / 9672
🟢 Functions 79.5% (🎯 60%) 1878 / 2362
🟢 Branches 76.54% (🎯 60%) 4400 / 5748
File CoverageNo changed files found.
Generated in workflow #1878 for commit 3099a0f by the Vitest Coverage Report Action
kilo-code-bot[bot]commented· last week

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Files Reviewed (1 files)
  • tests/ci/dependabot-automerge-contract.test.ts

Reviewed by free · Input: 0 · Output: 0 · Cached: 0

Sign in to comment.

Merge readiness

Checking mergeability after the indexing worker computes the current branch state.

Autopilot

Debug

Reviews

Approved0
ReviewersNone yet

Configure an OpenRouter key in repository settings.