Skip to content

Merge Dependabot MR #429

Merge Dependabot MR

Merge Dependabot MR #429

---
# https://github.blog/changelog/2021-02-19-github-actions-workflows-triggered-by-dependabot-prs-will-run-with-read-only-permissions/
# https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
name: Merge Dependabot MR
# read-write repo token
# access to secrets
on:
workflow_run:
workflows:
- CI
types:
- completed
branches:
- 'dependabot/**'
jobs:
merge:
runs-on: ubuntu-latest
if: >-
github.event.workflow_run.event == 'pull_request' &&
github.event.workflow_run.conclusion == 'success'
steps:
- name: Merge
uses: ridedott/merge-me-action@v2
with:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}