This commit is contained in:
Barry Gordon
2022-02-28 18:14:28 +00:00
parent 0ca01a5553
commit 11d3bb752a
3 changed files with 8 additions and 8 deletions

View File

@@ -10,7 +10,7 @@ Extract information about the dependencies being updated by a Dependabot-generat
## Usage instructions
Create a workflow file that contains a step that uses: `dependabot/fetch-metadata@v1.2.1`, e.g.
Create a workflow file that contains a step that uses: `dependabot/fetch-metadata@v1.3.0`, e.g.
```yaml
-- .github/workflows/dependabot-prs.yml
@@ -22,7 +22,7 @@ jobs:
steps:
- name: Fetch Dependabot metadata
id: dependabot-metadata
uses: dependabot/fetch-metadata@v1.2.1
uses: dependabot/fetch-metadata@v1.3.0
with:
alert-lookup: true
compat-lookup: true
@@ -93,7 +93,7 @@ jobs:
steps:
- name: Dependabot metadata
id: dependabot-metadata
uses: dependabot/fetch-metadata@v1.2.1
uses: dependabot/fetch-metadata@v1.3.0
- name: Approve a PR
run: gh pr review --approve "$PR_URL"
env:
@@ -121,7 +121,7 @@ jobs:
steps:
- name: Dependabot metadata
id: dependabot-metadata
uses: dependabot/fetch-metadata@v1.2.1
uses: dependabot/fetch-metadata@v1.3.0
- name: Enable auto-merge for Dependabot PRs
if: ${{contains(steps.dependabot-metadata.outputs.dependency-names, 'rails') && steps.dependabot-metadata.outputs.update-type == 'version-update:semver-patch'}}
run: gh pr merge --auto --merge "$PR_URL"
@@ -150,7 +150,7 @@ jobs:
steps:
- name: Dependabot metadata
id: dependabot-metadata
uses: dependabot/fetch-metadata@v1.2.1
uses: dependabot/fetch-metadata@v1.3.0
- name: Add a label for all production dependencies
if: ${{ steps.dependabot-metadata.outputs.dependency-type == 'direct:production' }}
run: gh pr edit "$PR_URL" --add-label "production"

4
package-lock.json generated
View File

@@ -1,12 +1,12 @@
{
"name": "dependabot-pull-request-action",
"version": "1.2.1",
"version": "1.3.0",
"lockfileVersion": 2,
"requires": true,
"packages": {
"": {
"name": "dependabot-pull-request-action",
"version": "1.2.1",
"version": "1.3.0",
"license": "MIT",
"dependencies": {
"@actions/core": "^1.6.0",

View File

@@ -1,6 +1,6 @@
{
"name": "dependabot-pull-request-action",
"version": "1.2.1",
"version": "1.3.0",
"description": "Parse Dependabot commit metadata to automate PR handling",
"main": "dist/index.js",
"scripts": {