apache / apache/logging-parent

Adapt `merge-dependabot-reusable` to support RTC workflow

Open
#417 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
FreeMarker
Stars
6
Forks
8
Avg merge
1d 13h
Merged PRs (30d)
6

Description

With the introduction of the **Review-to-Commit** process, the current `merge-dependabot-reusable` GitHub Actions workflow needs to be revised. The RTC policy introduces new constraints that directly impact how Dependabot PRs can be processed and merged.

## Problems

1. **Review requirement:**
The workflow can no longer merge PRs directly, as the RTC policy mandates at least one code review before merging.

2. **Triggering required checks:**
Any commits made by the workflow (e.g., adding changelog files) must trigger all required status checks. This behavior is only guaranteed if the workflow uses a **Personal Access Token (PAT)** with appropriate permissions, instead of the default `GITHUB_TOKEN`.

3. **Support for maintainers:**
To ease the additional manual steps introduced by RTC, the updated workflow should:

* Handle PRs that update **multiple dependencies at once** (e.g., bundler mode).
* Enable **GitHub's auto-merge** feature after making its changes, so the PR merges automatically once it receives a review and passes checks.

## Propose solution

* Create a new reusable workflow (e.g., `process-dependabot-reusable`) that addresses these constraints.
* Ensure it uses a PAT to push changelog updates and re-run checks.
* Add logic to support multi-dependency updates and enable auto-merge.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by locating the existing `merge-dependabot-reusable` workflow and review the RTC constraints described here. Check how the replacement reusable workflow would use a PAT, handle multi-dependency updates, and enable GitHub auto-merge. Done means reviewed Dependabot PRs satisfy RTC requirements, required checks trigger after changelog changes, and eligible PRs auto-merge after approval and passing checks.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.