Skip to content

CI: Run Check Updates on merge_group - #679

Merged
bupd merged 1 commit into
mainfrom
ci-check-updates-merge-group
Sep 22, 2026
Merged

bupd merged 1 commit into
mainfrom
ci-check-updates-merge-group

Conversation

@bupd

@bupd bupd commented Sep 22, 2026

Copy link
Copy Markdown
Member

Follow-up to #678. Adds merge_group: trigger to check_updates.yml so every workflow runs on queue branches. The Create Pull Request step is skipped on merge_group so queue runs never open update PRs.

🤖 Generated with Claude Code

Queue branches should exercise the nvchecker run like any other
check, but never open update PRs from a gh-readonly-queue ref.

Signed-off-by: Prasanth Baskar <prasanth@8gears.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 22, 2026 17:08
@bupd
bupd enabled auto-merge September 22, 2026 17:08
@bupd
bupd added this pull request to the merge queue Sep 22, 2026
Merged via the queue into main with commit 604f7e0 Sep 22, 2026
2 of 3 checks passed
@bupd
bupd deleted the ci-check-updates-merge-group branch September 22, 2026 17:09

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Merge-group execution must use a separate read-only job or workflow.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds merge-queue support to the package update workflow while preventing queued runs from creating pull requests.

Changes:

  • Adds the merge_group trigger.
  • Skips pull-request creation for merge-group runs.
  • Identifies a critical token-permission risk requiring workflow separation.
File Summary
.github/​workflows/​check_updates.yml Merge-group runs execute repository-controlled code with write-capable permissions, creating a potential GITHUB_TOKEN exfiltration risk.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

branches: [main]
pull_request:
branches: [main]
merge_group:
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants