Skip to content

ci: refresh bun.lock on Dependabot npm branches - #55

Merged
code-yeongyu merged 2 commits into
mainfrom
ci/dependabot-bun-lock
Oct 9, 2026
Merged

code-yeongyu merged 2 commits into
mainfrom
ci/dependabot-bun-lock

Conversation

@code-yeongyu

@code-yeongyu code-yeongyu commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Problem

Dependabot's npm updater rewrites package.json and package-lock.json but never bun.lock. ci.yml installs with bun install --frozen-lockfile, so every npm Dependabot PR fails all four test legs at install time, before any test runs. #53 and #54 failed exactly that way, and each needed a hand-pushed bun.lock refresh.

Change

New workflow .github/workflows/dependabot-bun-lock.yml. It runs only on pushes to dependabot/npm_and_yarn/** branches, and only when the actor is dependabot[bot].

Steps:

  1. Check out with persist-credentials: false.
  2. bun install --ignore-scripts with Bun 1.4.2, the version CI uses. Dependency lifecycle scripts never run, because this job holds a write token.
  3. If bun.lock didn't change, stop.
  4. If anything other than bun.lock changed, fail loudly instead of committing.
  5. Otherwise commit only bun.lock as github-actions[bot], push it to the same branch, and start ci.yml on it with workflow_dispatch. A commit pushed with GITHUB_TOKEN starts no workflow on its own, which also means the workflow can't loop on its own push.

Permissions:

  • Workflow default: contents: read.
  • The one job: contents: write to push bun.lock, and actions: write to dispatch CI. Dependabot-triggered workflows get a read-only token unless the workflow raises it this way.

package-lock.json stays: the npm-consumer job uses it.

Notes

  • Once this bot commits on a Dependabot branch, Dependabot stops auto-rebasing that PR. A newer bump replaces it, or @dependabot recreate starts it over; the new branch is then refreshed again.
  • Validation: actionlint is clean on the new file and on ci.yml. The real test is the next npm Dependabot PR: it should get a build(deps): refresh bun.lock commit, then a green CI run on that commit.

View guided diff

@code-yeongyu
code-yeongyu force-pushed the ci/dependabot-bun-lock branch from da42d3a to 6930201 Compare October 9, 2026 07:32
@code-yeongyu
code-yeongyu merged commit 0737d8b into main Oct 9, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant