Bump tar from 7.5.1 to 7.5.2 in the npm_and_yarn group across 1 directory #320
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Dependabot reviewer | |
| on: pull_request_target | |
| permissions: | |
| pull-requests: write | |
| contents: write | |
| jobs: | |
| review-dependabot-pr: | |
| runs-on: ubuntu-latest | |
| if: ${{ github.event.pull_request.user.login == 'dependabot[bot]' }} | |
| steps: | |
| - name: Dependabot metadata | |
| id: dependabot-metadata | |
| uses: dependabot/[email protected] | |
| - name: Approve and auto-merge minor and patch updates | |
| if: ${{ steps.dependabot-metadata.outputs.update-type == 'version-update:semver-patch' || steps.dependabot-metadata.outputs.update-type == 'version-update:semver-minor' }} | |
| run: | | |
| gh pr review "$PR_URL" --approve -b "✅ Auto-approved: This pull request includes a **patch** or **minor** update." | |
| gh pr merge "$PR_URL" --squash --auto | |
| env: | |
| PR_URL: ${{ github.event.pull_request.html_url }} | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Require manual review for major updates | |
| if: ${{ steps.dependabot-metadata.outputs.update-type == 'version-update:semver-major' }} | |
| run: | | |
| gh pr review "$PR_URL" --comment -b "⚠️ This pull request includes a **major update**. Manual approval from a repo admin is required before merging." | |
| env: | |
| PR_URL: ${{ github.event.pull_request.html_url }} | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} |