Skip to content

github: scope/narrow permissions, prevent template injection via GHA, enable zizmor workflow #10681

github: scope/narrow permissions, prevent template injection via GHA, enable zizmor workflow

github: scope/narrow permissions, prevent template injection via GHA, enable zizmor workflow #10681

Workflow file for this run

name: Enable auto-merge for Dependabot PRs
on:
pull_request:
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions: {}
jobs:
dependabot-auto-merge:
name: 'Dependabot auto-merge'
permissions:
contents: write
pull-requests: write
runs-on: ubuntu-latest
if: ${{ github.actor == 'dependabot[bot]' }}
steps:
- name: Enable auto-merge for Dependabot PRs
run: gh pr merge --auto --rebase "$PR_URL"
env:
PR_URL: ${{github.event.pull_request.html_url}}
GITHUB_TOKEN: ${{secrets.GITHUB_TOKEN}}