Skip to content

ci: rebuild bundles for Dependabot npm updates - #162

Merged
chenrui333 merged 1 commit into
masterfrom
ci/dependabot-bundle
Sep 7, 2026
Merged

chenrui333 merged 1 commit into
masterfrom
ci/dependabot-bundle

Conversation

@chenrui333

Copy link
Copy Markdown
Collaborator

Summary

Dependabot npm updates change the dependency manifests without rebuilding dist/index.js, leaving PRs such as #161 failing the bundle freshness check.

Upload the rebuilt bundle after read-only CI checks, then use a separate workflow to commit only dist/index.js onto eligible Dependabot PRs and dispatch fresh CI. The updater validates the author, repository, changed paths, artifact, and current head, and rejects concurrent head changes. PR code never runs in the write-enabled job.

Notes

The updater becomes active after this PR merges and uses GITHUB_TOKEN without additional secrets. The bundle freshness check remains enabled.

References

Signed-off-by: Rui Chen <rui@chenrui.dev>
@chenrui333
chenrui333 merged commit 6b1ac56 into master Sep 7, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant