Skip to content

[ci]: let pure Dependabot action-ref bumps pass the review guard - #3

Merged
effecet merged 1 commit into
mainfrom
ci/dependabot-ref-bumps
Oct 5, 2026
Merged

effecet merged 1 commit into
mainfrom
ci/dependabot-ref-bumps

Conversation

@effecet

@effecet effecet commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Lets a Dependabot PR that only bumps action refs pass the review check without a Claude verdict. claude-code-action skips itself on a PR that edits claude-review.yml, so until now every such bump needed an admin bypass merge.

The exemption requires all of:

  • github.actor is dependabot[bot], and every PR commit is authored by dependabot[bot], committed by web-flow and GitHub-verified, so extra pushes onto the branch void it;
  • every changed file is an existing .github/workflows/*.yml (no renames, mode changes, new or deleted files);
  • every changed line is a uses: owner/action@ref whose removed and added versions pair up in order with the same indent and action name.

Anything else still fails and needs a human merge.

Tested against 22 diffs: the 4 real checkout bumps merged by hand on 2026-10-04 pass; 12 crafted bypasses (action swap hidden in a comment, rename out of workflows, moved steps, hidden lines, new files, ...) fail. Reviewed by a security auditor and a bug-hunter (two rounds each); actionlint clean.

This PR edits claude-review.yml itself, so the Claude review skips it by design.

🤖 Generated with Claude Code

claude-code-action skips itself on a PR that edits claude-review.yml, so
every Dependabot bump of an action used there failed the required
`review` check and needed an admin bypass merge.

The enforce step now passes such a PR without a Claude verdict only when
all of these hold:
- github.actor is dependabot[bot], and every PR commit is authored by
  dependabot[bot], committed by web-flow and GitHub-verified (so nobody
  can push extra changes onto the branch and ride the exemption);
- every changed file is an existing .github/workflows/*.yml (no
  renames, mode changes, new or deleted files);
- every changed line is a `uses: owner/action@ref` whose removed and
  added versions pair up in order with the same indent and action name.

Anything else still fails and needs a human merge. Checked against 22
diffs: the 4 real checkout bumps merged by hand on 2026-10-04 pass; 12
crafted bypasses (action swap via comment, rename out of workflows,
moved steps, hidden lines, new files, ...) fail.
@effecet
effecet merged commit 8e7f8dc into main Oct 5, 2026
1 check passed
@effecet
effecet deleted the ci/dependabot-ref-bumps branch October 5, 2026 01:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant