Skip to content

chore(deps): update all non-major dependencies #5835

chore(deps): update all non-major dependencies

chore(deps): update all non-major dependencies #5835

# Copyright Red Hat, Inc.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
name: Auto-Approve Bot PRs
# This workflow automatically adds labels and approves PRs that match specific criteria:
# - Created by rhdh-bot (via RHDH GitHub App)
# - Branch name matches specific patterns (base image updates, version bumps, etc.)
# - Adds lgtm and approved labels if not present
#
# pull_request_target runs this file from the *base* branch, so every release-*
# line needs the same debounce. updateBaseImages.sh opens the PR on the first
# image bump and pushes another commit seconds later; Prow then strips lgtm.
# Wait 10s after the triggering commit and skip if HEAD moved. A later
# synchronize run (with cancel-in-progress) applies lgtm 10s after the last push.
# labeled is omitted so adding lgtm/approved does not retrigger this workflow.
on:
pull_request_target:
types: [opened, reopened, synchronize, ready_for_review]
concurrency:
group: auto-approve-pr-${{ github.event.pull_request.number }}
cancel-in-progress: true
permissions:
contents: read
pull-requests: write
issues: write
jobs:
auto-approve:
name: Auto-Approve and Label PRs
runs-on: ubuntu-latest
# Only run if PR is from rhdh-bot
if: github.event.pull_request.user.login == 'rhdh-bot'
steps:
- name: Check PR eligibility
id: check-eligibility
env:
PR_BRANCH: ${{ github.event.pull_request.head.ref }}
PR_DRAFT: ${{ github.event.pull_request.draft }}
run: |
# Don't auto-approve draft PRs
if [[ "$PR_DRAFT" == "true" ]]; then
echo "eligible=false" >> $GITHUB_OUTPUT
echo "reason=PR is in draft state" >> $GITHUB_OUTPUT
exit 0
fi
# Labels will be added automatically if eligible
# Define branch patterns that are eligible for auto-approval
# Add more patterns as needed
ELIGIBLE_PATTERNS=(
"^chore/automated-.*"
)
ELIGIBLE=false
for pattern in "${ELIGIBLE_PATTERNS[@]}"; do
if [[ "$PR_BRANCH" =~ $pattern ]]; then
ELIGIBLE=true
break
fi
done
if [[ "$ELIGIBLE" == "true" ]]; then
echo "eligible=true" >> $GITHUB_OUTPUT
else
echo "eligible=false" >> $GITHUB_OUTPUT
fi
- name: Wait until HEAD is stable
id: debounce
if: steps.check-eligibility.outputs.eligible == 'true'
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_NUMBER: ${{ github.event.pull_request.number }}
EVENT_SHA: ${{ github.event.pull_request.head.sha }}
run: |
DEBOUNCE_SECONDS=10
echo "Waiting ${DEBOUNCE_SECONDS}s after ${EVENT_SHA} so later commits can land and Prow can process synchronize."
sleep "${DEBOUNCE_SECONDS}"
CURRENT_SHA=$(gh pr view "$PR_NUMBER" --repo "$GITHUB_REPOSITORY" --json headRefOid --jq .headRefOid)
if [[ "${CURRENT_SHA}" != "${EVENT_SHA}" ]]; then
echo "HEAD moved during debounce (${EVENT_SHA} -> ${CURRENT_SHA}); skipping so the newer run can label."
echo "stable=false" >> "$GITHUB_OUTPUT"
exit 0
fi
echo "HEAD unchanged for ${DEBOUNCE_SECONDS}s: ${CURRENT_SHA}"
echo "stable=true" >> "$GITHUB_OUTPUT"
- name: Add required labels and approve PR
if: steps.check-eligibility.outputs.eligible == 'true' && steps.debounce.outputs.stable == 'true'
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_NUMBER: ${{ github.event.pull_request.number }}
run: |
# Add the required labels if not already present
gh pr edit "$PR_NUMBER" --add-label "lgtm,approved" --repo "$GITHUB_REPOSITORY"
# Auto-approve the PR
gh pr review "$PR_NUMBER" \
--approve \
--repo "$GITHUB_REPOSITORY" \
--body "**Auto-Approved**
This PR has been automatically approved by the auto-approve workflow.
/override ci/prow/e2e-ocp-helm
**Labels Added:** \`lgtm\`, \`approved\`"