From 40476e7be957230462d30543900b7166ed5e9d10 Mon Sep 17 00:00:00 2001 From: Alexander Petric Date: Wed, 23 Sep 2026 06:59:50 -0400 Subject: [PATCH] ci: skip the AI reviews and the Discord notice on Dependabot PRs (#11307) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * ci: skip the AI reviews and the Discord notice on Dependabot PRs They already do not review them, they just fail while doing so. The Claude action rejects a bot actor outright ("Workflow initiated by non-human actor"), and the Codex and Pi jobs find no API key because GitHub gives Dependabot- triggered runs a separate secret scope from Actions. Verified on #11302: zero reviews posted, the only comment is a Cloudflare deployment notice, while codex-review and pi-review both reported success. So every Dependabot PR carried two permanently red checks that meant nothing, which is the worst kind of signal — it buries a Dependabot PR that genuinely is broken, and a green tick that means "skipped" reads exactly like one that means "looked and approved". Skipping states it honestly. The workflow_call branch is untouched, so a review can still be requested on a specific bot PR when the diff deserves one, which is worth doing for a grouped security update that swaps a cipher or drops a parser rather than just moving a version. The Discord notice is excluded for the same reason plus its own: nobody wants a forum thread per lockfile bump. Not fixed here, deliberately: making these actually review bot PRs would need the org's review credentials copied into the Dependabot secret scope, which is a wider grant than this is worth given the PRs in question are lockfile diffs. Co-Authored-By: Claude Opus 5 (1M context) * ci: gate the close-time Discord job too, and trim the comments Both reviewers caught the same gap: merge_success_emoji runs on every `closed` event with no exclusion, and the reusable workflow it calls exits 1 when it cannot find a thread. Since open_thread no longer creates one for Dependabot, the failure would have moved from open-time to merge-time rather than going away. Gated to match. The comments are cut from eight lines to two per file. AGENTS.md:205 asks for constraints in <=4 lines, stated once, describing the code as it is — mine narrated the drafting history and argued the change to a reviewer, both of which belong in the PR description. Also drops "bot-authored", which overstated a condition that only covers dependabot[bot]. Co-Authored-By: Claude Opus 5 (1M context) --------- Co-authored-by: Claude Opus 5 (1M context) --- .github/workflows/codex-pr-review.yml | 5 ++++- .github/workflows/discord-notification.yml | 6 ++++-- .github/workflows/pi-pr-review.yml | 5 ++++- .github/workflows/pr-ready-review.yml | 5 ++++- 4 files changed, 16 insertions(+), 5 deletions(-) diff --git a/.github/workflows/codex-pr-review.yml b/.github/workflows/codex-pr-review.yml index 354e8a60ca..55036776c6 100644 --- a/.github/workflows/codex-pr-review.yml +++ b/.github/workflows/codex-pr-review.yml @@ -40,11 +40,14 @@ jobs: # an author_association gate: the pull_request webhook payload reports private org # members as CONTRIBUTOR/NONE (only public members show as MEMBER), which silently # skips auto-review for every private member. + # Dependabot-triggered runs get a separate secret scope, so this job has no API + # key and cannot review. workflow_call stays open for an explicit request. if: | github.event_name == 'workflow_call' || ( github.event.pull_request.draft == false && - github.event.pull_request.head.repo.fork == false + github.event.pull_request.head.repo.fork == false && + github.event.pull_request.user.login != 'dependabot[bot]' ) permissions: contents: read diff --git a/.github/workflows/discord-notification.yml b/.github/workflows/discord-notification.yml index d731faafd9..c83cbc90d3 100644 --- a/.github/workflows/discord-notification.yml +++ b/.github/workflows/discord-notification.yml @@ -13,7 +13,8 @@ on: jobs: notify_discord_when_pr_opened: - if: (github.event.pull_request.draft == false) && (github.event.action == 'opened' || github.event.action == 'ready_for_review') + # No thread is opened for Dependabot PRs, so nothing downstream may assume one. + if: (github.event.pull_request.draft == false) && (github.event.action == 'opened' || github.event.action == 'ready_for_review') && (github.event.pull_request.user.login != 'dependabot[bot]') uses: ./.github/workflows/shareable-discord-notification.yml with: PR_TITLE: ${{ github.event.pull_request.title }} @@ -28,7 +29,8 @@ jobs: DISCORD_BOT_TOKEN: ${{ secrets.DISCORD_AI_BOT_TOKEN }} merge_success_emoji: - if: github.event.action == 'closed' + # Must match open_thread's exclusion: this reacts to a thread that was never created. + if: github.event.action == 'closed' && github.event.pull_request.user.login != 'dependabot[bot]' uses: ./.github/workflows/shareable-discord-notification.yml with: PR_STATUS: "merged" diff --git a/.github/workflows/pi-pr-review.yml b/.github/workflows/pi-pr-review.yml index a89275cfb5..a18dc28ff2 100644 --- a/.github/workflows/pi-pr-review.yml +++ b/.github/workflows/pi-pr-review.yml @@ -38,11 +38,14 @@ jobs: # an author_association gate: the pull_request webhook payload reports private org # members as CONTRIBUTOR/NONE (only public members show as MEMBER), which silently # skips auto-review for every private member. + # Dependabot-triggered runs get a separate secret scope, so this job has no API + # key and cannot review. workflow_call stays open for an explicit request. if: | github.event_name == 'workflow_call' || ( github.event.pull_request.draft == false && - github.event.pull_request.head.repo.fork == false + github.event.pull_request.head.repo.fork == false && + github.event.pull_request.user.login != 'dependabot[bot]' ) permissions: contents: read diff --git a/.github/workflows/pr-ready-review.yml b/.github/workflows/pr-ready-review.yml index 4bfb5b4147..5e5c6a8c61 100644 --- a/.github/workflows/pr-ready-review.yml +++ b/.github/workflows/pr-ready-review.yml @@ -37,11 +37,14 @@ jobs: # an author_association gate: the pull_request webhook payload reports private org # members as CONTRIBUTOR/NONE (only public members show as MEMBER), which silently # skips auto-review for every private member. + # Dependabot-triggered runs get a separate secret scope, so this job has no API + # key and cannot review. workflow_call stays open for an explicit request. if: | github.event_name == 'workflow_call' || ( (github.event.pull_request.draft == false || github.event.pull_request.ready_for_review == true) && - github.event.pull_request.head.repo.fork == false + github.event.pull_request.head.repo.fork == false && + github.event.pull_request.user.login != 'dependabot[bot]' ) permissions: contents: read