mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-10-05 00:02:24 +00:00
ci: skip the AI reviews and the Discord notice on Dependabot PRs (#11307)
* ci: skip the AI reviews and the Discord notice on Dependabot PRs
They already do not review them, they just fail while doing so. The Claude
action rejects a bot actor outright ("Workflow initiated by non-human actor"),
and the Codex and Pi jobs find no API key because GitHub gives Dependabot-
triggered runs a separate secret scope from Actions. Verified on #11302: zero
reviews posted, the only comment is a Cloudflare deployment notice, while
codex-review and pi-review both reported success.
So every Dependabot PR carried two permanently red checks that meant nothing,
which is the worst kind of signal — it buries a Dependabot PR that genuinely is
broken, and a green tick that means "skipped" reads exactly like one that means
"looked and approved".
Skipping states it honestly. The workflow_call branch is untouched, so a review
can still be requested on a specific bot PR when the diff deserves one, which is
worth doing for a grouped security update that swaps a cipher or drops a parser
rather than just moving a version.
The Discord notice is excluded for the same reason plus its own: nobody wants a
forum thread per lockfile bump.
Not fixed here, deliberately: making these actually review bot PRs would need
the org's review credentials copied into the Dependabot secret scope, which is a
wider grant than this is worth given the PRs in question are lockfile diffs.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* ci: gate the close-time Discord job too, and trim the comments
Both reviewers caught the same gap: merge_success_emoji runs on every `closed`
event with no exclusion, and the reusable workflow it calls exits 1 when it
cannot find a thread. Since open_thread no longer creates one for Dependabot,
the failure would have moved from open-time to merge-time rather than going
away. Gated to match.
The comments are cut from eight lines to two per file. AGENTS.md:205 asks for
constraints in <=4 lines, stated once, describing the code as it is — mine
narrated the drafting history and argued the change to a reviewer, both of which
belong in the PR description. Also drops "bot-authored", which overstated a
condition that only covers dependabot[bot].
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
318f89960e
commit
40476e7be9
@@ -40,11 +40,14 @@ jobs:
|
||||
# an author_association gate: the pull_request webhook payload reports private org
|
||||
# members as CONTRIBUTOR/NONE (only public members show as MEMBER), which silently
|
||||
# skips auto-review for every private member.
|
||||
# Dependabot-triggered runs get a separate secret scope, so this job has no API
|
||||
# key and cannot review. workflow_call stays open for an explicit request.
|
||||
if: |
|
||||
github.event_name == 'workflow_call' ||
|
||||
(
|
||||
github.event.pull_request.draft == false &&
|
||||
github.event.pull_request.head.repo.fork == false
|
||||
github.event.pull_request.head.repo.fork == false &&
|
||||
github.event.pull_request.user.login != 'dependabot[bot]'
|
||||
)
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
@@ -13,7 +13,8 @@ on:
|
||||
|
||||
jobs:
|
||||
notify_discord_when_pr_opened:
|
||||
if: (github.event.pull_request.draft == false) && (github.event.action == 'opened' || github.event.action == 'ready_for_review')
|
||||
# No thread is opened for Dependabot PRs, so nothing downstream may assume one.
|
||||
if: (github.event.pull_request.draft == false) && (github.event.action == 'opened' || github.event.action == 'ready_for_review') && (github.event.pull_request.user.login != 'dependabot[bot]')
|
||||
uses: ./.github/workflows/shareable-discord-notification.yml
|
||||
with:
|
||||
PR_TITLE: ${{ github.event.pull_request.title }}
|
||||
@@ -28,7 +29,8 @@ jobs:
|
||||
DISCORD_BOT_TOKEN: ${{ secrets.DISCORD_AI_BOT_TOKEN }}
|
||||
|
||||
merge_success_emoji:
|
||||
if: github.event.action == 'closed'
|
||||
# Must match open_thread's exclusion: this reacts to a thread that was never created.
|
||||
if: github.event.action == 'closed' && github.event.pull_request.user.login != 'dependabot[bot]'
|
||||
uses: ./.github/workflows/shareable-discord-notification.yml
|
||||
with:
|
||||
PR_STATUS: "merged"
|
||||
|
||||
@@ -38,11 +38,14 @@ jobs:
|
||||
# an author_association gate: the pull_request webhook payload reports private org
|
||||
# members as CONTRIBUTOR/NONE (only public members show as MEMBER), which silently
|
||||
# skips auto-review for every private member.
|
||||
# Dependabot-triggered runs get a separate secret scope, so this job has no API
|
||||
# key and cannot review. workflow_call stays open for an explicit request.
|
||||
if: |
|
||||
github.event_name == 'workflow_call' ||
|
||||
(
|
||||
github.event.pull_request.draft == false &&
|
||||
github.event.pull_request.head.repo.fork == false
|
||||
github.event.pull_request.head.repo.fork == false &&
|
||||
github.event.pull_request.user.login != 'dependabot[bot]'
|
||||
)
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
@@ -37,11 +37,14 @@ jobs:
|
||||
# an author_association gate: the pull_request webhook payload reports private org
|
||||
# members as CONTRIBUTOR/NONE (only public members show as MEMBER), which silently
|
||||
# skips auto-review for every private member.
|
||||
# Dependabot-triggered runs get a separate secret scope, so this job has no API
|
||||
# key and cannot review. workflow_call stays open for an explicit request.
|
||||
if: |
|
||||
github.event_name == 'workflow_call' ||
|
||||
(
|
||||
(github.event.pull_request.draft == false || github.event.pull_request.ready_for_review == true) &&
|
||||
github.event.pull_request.head.repo.fork == false
|
||||
github.event.pull_request.head.repo.fork == false &&
|
||||
github.event.pull_request.user.login != 'dependabot[bot]'
|
||||
)
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
Reference in New Issue
Block a user