name: Approve & merge successful dependabot patch upgrade PRs on: pull_request permissions: pull-requests: read jobs: dependabot: runs-on: ubuntu-latest if: ${{ github.actor == 'dependabot[bot]' }} steps: - name: Dependabot metadata id: metadata uses: dependabot/fetch-metadata@v1 - name: Approve the PR & enable auto-merge if: ${{ steps.metadata.outputs.update-type == 'version-update:semver-patch' }} run: | gh pr review --approve "$PR_URL" gh pr merge --auto --merge "$PR_URL" env: PR_URL: ${{github.event.pull_request.html_url}} GH_TOKEN: ${{secrets.SERVO_DEPENDABOT_TOKEN}}