Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions .github/workflows/quality-gates.yml
Original file line number Diff line number Diff line change
Expand Up @@ -63,12 +63,25 @@ jobs:
vendored-patch-audit:
name: Dependency Audit Trail
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: read
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
fetch-depth: 0
# Routine Dependabot patch/minor bumps cannot author an audit doc, so
# exempt them (issue #2975). Resolve the bump type from Dependabot
# metadata; the step is skipped (and the gate enforced normally) for
# every non-Dependabot PR.
- name: Fetch Dependabot metadata
id: dependabot-metadata
if: github.actor == 'dependabot[bot]'
uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0
- env:
BASE_REF: ${{ github.base_ref }}
PR_ACTOR: ${{ github.actor }}
DEPENDABOT_UPDATE_TYPE: ${{ steps.dependabot-metadata.outputs.update-type }}
run: |
chmod +x scripts/ci/vendored-patch-audit.sh
scripts/ci/vendored-patch-audit.sh "origin/$BASE_REF"
18 changes: 18 additions & 0 deletions scripts/ci/vendored-patch-audit.sh
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,17 @@
#
# When lockfiles or vendored content changes, a corresponding entry must exist
# in docs/dependency-audits/ explaining what changed and why.
#
# Exception (issue #2975): routine Dependabot patch/minor bumps cannot author
# that doc by construction, so they are exempt when the caller sets
# PR_ACTOR=dependabot[bot] and DEPENDABOT_UPDATE_TYPE to a non-major update.
# This mirrors auto-merge-dependabot.yml, which already auto-merges exactly that
# set. Human PRs and Dependabot major bumps still require the doc.
set -euo pipefail

BASE_REF="${1:-origin/main}"
PR_ACTOR="${PR_ACTOR:-}"
DEPENDABOT_UPDATE_TYPE="${DEPENDABOT_UPDATE_TYPE:-}"

# Lockfile patterns across all SDK ecosystems
LOCK_PATTERNS=(
Expand Down Expand Up @@ -42,6 +50,16 @@ if [ "$LOCK_TOUCHED" = false ]; then
exit 0
fi

# Exempt routine Dependabot patch/minor bumps (issue #2975). "Not major"
# matches the auto-merge policy in auto-merge-dependabot.yml. Human PRs (no
# PR_ACTOR match) and Dependabot major bumps fall through and still need a doc.
if [ "$PR_ACTOR" = "dependabot[bot]" ] && \
[ -n "$DEPENDABOT_UPDATE_TYPE" ] && \
[ "$DEPENDABOT_UPDATE_TYPE" != "version-update:semver-major" ]; then
echo "✅ vendored-patch-audit: exempt — Dependabot $DEPENDABOT_UPDATE_TYPE bump (#2975)"
exit 0
fi

# Check for an audit doc
AUDIT_DOC=$(grep -E '^docs/dependency-audits/[0-9]{4}-[0-9]{2}-[0-9]{2}-.+\.md$' <<< "$CHANGED_FILES" || true)

Expand Down
Loading