Skip to content

ci: attach required checks to Dependabot PRs; peer pi-* >=0.87.1 - #56

Merged
code-yeongyu merged 2 commits into
mainfrom
ci/approve-bot-pr-run-and-peer-floor
Oct 9, 2026
Merged

code-yeongyu merged 2 commits into
mainfrom
ci/approve-bot-pr-run-and-peer-floor

Conversation

@code-yeongyu

@code-yeongyu code-yeongyu commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Follow-up to #55, #53 and #54. This is the same change as code-yeongyu/pi-comment-checker#21, Opus-reviewed there; the review fixes are included: the dispatch fallback is kept when gh run list fails, plus an accurate header comment.

1. Required checks on Dependabot PRs

On pi-comment-checker #19 (this repo has the same workflow and approval policy), the refresh workflow's bun.lock commit (pushed with GITHUB_TOKEN) did create a pull_request CI run, 37900166347. Because github-actions[bot] counts as a first-time contributor under this repo's approval policy (first_time_contributors), that run waited for approval, never ran any jobs, and ended as a failure after about 15 minutes. The workflow_dispatch run reported the required check names on the commit, but dispatched check suites have no PR association (pull_requests: []), so the PR rollup showed only GitGuardian and the merge needed --admin.

dependabot-bun-lock.yml now does this after its push:

  • it waits up to 60 s for that commit's pull_request run of ci.yml, then approves it (POST /actions/runs/{id}/approve, using the job's existing actions: write), so the required checks run on the PR itself;
  • if no run is found or the approval is refused, it logs a warning and dispatches ci.yml as before. The result is never worse than today.

Unverified: whether the approve endpoint accepts a same-repo run, since GitHub documents it for fork PRs from first-time contributors. This can't be exercised outside a real Dependabot push. The next npm Dependabot PR will show either approved pull_request run <id> or the fallback warning in the refresh job's log.

2. Peer range

peerDependencies on @earendil-works/pi-ai, pi-coding-agent and pi-tui change from * to >=0.87.1. Development now tests against pi 1.0.4, so I checked the old floor. With every @earendil-works package pinned to 0.87.1 (installed versions verified in node_modules), bun run typecheck reports 0 errors and bun run test passes 76/76. That covers typecheck and the unit tests, not a live pi -e load. Below 0.87.1 is untested, which is why the range no longer claims it. bun.lock and package-lock.json are regenerated to match.

Checks

  • Frozen install, tests (76/76) and bun run check pass.
  • actionlint is clean on all workflows.
  • CHANGELOG updated under [Unreleased].

View guided diff

@code-yeongyu
code-yeongyu merged commit fe83e11 into main Oct 9, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant