Skip to content

fix: detect Dependabot security PRs by cross-checking alerts, not body text - #284

Merged
ianmcburnie merged 2 commits into
masterfrom
fix/dependabot-automerge-security-detection
Sep 30, 2026
Merged

ianmcburnie merged 2 commits into
masterfrom
fix/dependabot-automerge-security-detection

Conversation

@ianmcburnie

Copy link
Copy Markdown
Member

Summary

  • The auto-merge workflow's is_security check grep'd the PR body for literal GHSA-/CVE- strings, but Dependabot doesn't reliably include those in every security-update PR body — so some security bumps get silently skipped by auto-merge instead of merged.
  • Found this while porting the same workflow's fix over from a sibling repo, where none of several genuine security-fix PRs (confirmed against open Dependabot alerts) had a GHSA/CVE string in the body.
  • Now the bumped package name is parsed from the PR title and cross-checked against the repo's actual open Dependabot alerts via the API.
  • Also added a few retries around the merge step to ride out the brief window where branch protection hasn't caught up with the just-completed CI run yet.

Test plan

  • Confirm the next Dependabot security PR (e.g. one of the currently open alerts: brace-expansion, form-data, js-yaml, qs, request, smol-toml, tar, tough-cookie, uuid) gets correctly detected and auto-merged

ianmcburnie and others added 2 commits September 29, 2026 16:55
…y text

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@ianmcburnie
ianmcburnie merged commit e87dee2 into master Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant