Skip to content

feat(npm-audit): Add automerge workflow for npm-audit-fix - #792

Merged
susnux merged 4 commits into
masterfrom
feat/noid/npm-audit-automerge
Sep 16, 2026
Merged

susnux merged 4 commits into
masterfrom
feat/noid/npm-audit-automerge

Conversation

@nickvergessen

Copy link
Copy Markdown
Member

🤖 AI (if applicable)

  • The content of this PR was partly or fully generated using AI (N/A)

Assisted-by: ClaudeCode:claude-sonnet-5
Signed-off-by: Joas Schilling <coding@schilljs.com>
Assisted-by: ClaudeCode:claude-sonnet-5
Signed-off-by: Joas Schilling <coding@schilljs.com>
@nickvergessen nickvergessen self-assigned this Sep 15, 2026
@nickvergessen nickvergessen added the 3. to review Waiting for reviews label Sep 15, 2026
@nextcloud-command nextcloud-command added the AI assisted This PR contains AI-assisted commits label Sep 15, 2026

@susnux susnux left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

should we merge this into one workflow (maybe separate steps)?

@nickvergessen

Copy link
Copy Markdown
Member Author

Same question applies to nextcloud/ocp updates I guess.
Not sure why it was not done in first place. Can imagine few reasons:

  • Copied from dependabot (can not merge files and simply copied over)
  • Did not work in the past (auto-merge github action on a github actioned PR, I think it rings a bell)
  • Could be "annoying" if someone wants to not automerge (but we could have an easy opt-out with a patch file)

@susnux

susnux commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Copied from dependabot (can not merge files and simply copied over)

I guess thats the reason

@susnux susnux left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ok for me, but I think its better maintainable as one workflow with opt-out with a patch.
otherwise you loose track of all the workflows at some point.

Assisted-by: ClaudeCode:claude-sonnet-5
Signed-off-by: Joas Schilling <coding@schilljs.com>
@nickvergessen

Copy link
Copy Markdown
Member Author

I think its better maintainable as one workflow with opt-out with a patch.
otherwise you loose track of all the workflows at some point.

Done that now. Will give it a test in an app

@nickvergessen

Copy link
Copy Markdown
Member Author

Successful run in nextcloud/upload_monitor#164

Signed-off-by: Joas Schilling <coding@schilljs.com>
@susnux
susnux merged commit 1d5c283 into master Sep 16, 2026
6 checks passed
@susnux
susnux deleted the feat/noid/npm-audit-automerge branch September 16, 2026 09:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews AI assisted This PR contains AI-assisted commits

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants