[ci]: let pure Dependabot action-ref bumps pass the review guard - #3
Merged
Merged
Conversation
claude-code-action skips itself on a PR that edits claude-review.yml, so every Dependabot bump of an action used there failed the required `review` check and needed an admin bypass merge. The enforce step now passes such a PR without a Claude verdict only when all of these hold: - github.actor is dependabot[bot], and every PR commit is authored by dependabot[bot], committed by web-flow and GitHub-verified (so nobody can push extra changes onto the branch and ride the exemption); - every changed file is an existing .github/workflows/*.yml (no renames, mode changes, new or deleted files); - every changed line is a `uses: owner/action@ref` whose removed and added versions pair up in order with the same indent and action name. Anything else still fails and needs a human merge. Checked against 22 diffs: the 4 real checkout bumps merged by hand on 2026-10-04 pass; 12 crafted bypasses (action swap via comment, rename out of workflows, moved steps, hidden lines, new files, ...) fail.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Lets a Dependabot PR that only bumps action refs pass the
reviewcheck without a Claude verdict. claude-code-action skips itself on a PR that edits claude-review.yml, so until now every such bump needed an admin bypass merge.The exemption requires all of:
github.actorisdependabot[bot], and every PR commit is authored bydependabot[bot], committed byweb-flowand GitHub-verified, so extra pushes onto the branch void it;.github/workflows/*.yml(no renames, mode changes, new or deleted files);uses: owner/action@refwhose removed and added versions pair up in order with the same indent and action name.Anything else still fails and needs a human merge.
Tested against 22 diffs: the 4 real checkout bumps merged by hand on 2026-10-04 pass; 12 crafted bypasses (action swap hidden in a comment, rename out of workflows, moved steps, hidden lines, new files, ...) fail. Reviewed by a security auditor and a bug-hunter (two rounds each); actionlint clean.
This PR edits claude-review.yml itself, so the Claude review skips it by design.
🤖 Generated with Claude Code