apache / apache/logging-parent
Adapt `merge-dependabot-reusable` to support RTC workflow
- Dominant language
- FreeMarker
- Stars
- 6
- Forks
- 8
- Avg merge
- 1d 13h
- Merged PRs (30d)
- 6
Description
With the introduction of the **Review-to-Commit** process, the current `merge-dependabot-reusable` GitHub Actions workflow needs to be revised. The RTC policy introduces new constraints that directly impact how Dependabot PRs can be processed and merged.
## Problems
1. **Review requirement:**
The workflow can no longer merge PRs directly, as the RTC policy mandates at least one code review before merging.
2. **Triggering required checks:**
Any commits made by the workflow (e.g., adding changelog files) must trigger all required status checks. This behavior is only guaranteed if the workflow uses a **Personal Access Token (PAT)** with appropriate permissions, instead of the default `GITHUB_TOKEN`.
3. **Support for maintainers:**
To ease the additional manual steps introduced by RTC, the updated workflow should:
* Handle PRs that update **multiple dependencies at once** (e.g., bundler mode).
* Enable **GitHub's auto-merge** feature after making its changes, so the PR merges automatically once it receives a review and passes checks.
## Propose solution
* Create a new reusable workflow (e.g., `process-dependabot-reusable`) that addresses these constraints.
* Ensure it uses a PAT to push changelog updates and re-run checks.
* Add logic to support multi-dependency updates and enable auto-merge.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by locating the existing `merge-dependabot-reusable` workflow and review the RTC constraints described here. Check how the replacement reusable workflow would use a PAT, handle multi-dependency updates, and enable GitHub auto-merge. Done means reviewed Dependabot PRs satisfy RTC requirements, required checks trigger after changelog changes, and eligible PRs auto-merge after approval and passing checks.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100