Skip to content

Enable Dependabot auto-merge#60383

Merged
nunomaduro merged 1 commit into
13.xfrom
chore/dependabot-auto-merge
Jun 4, 2026
Merged

Enable Dependabot auto-merge#60383
nunomaduro merged 1 commit into
13.xfrom
chore/dependabot-auto-merge

Conversation

@nunomaduro

@nunomaduro nunomaduro commented Jun 4, 2026

Copy link
Copy Markdown
Member

Adds a thin workflow that calls the shared reusable dependabot-auto-merge workflow in laravel/.github (pinned by commit SHA), which squash-merges this repo's grouped Dependabot github-actions PRs automatically. Patch and minor bumps only; majors (and other ecosystems) stay open for review.

@nunomaduro nunomaduro merged commit 1aa33be into 13.x Jun 4, 2026
59 checks passed
@nunomaduro nunomaduro deleted the chore/dependabot-auto-merge branch June 4, 2026 08:11
@browner12

Copy link
Copy Markdown
Contributor

This seems really not in the spirit of this whole security hardening that's going on. We're trying to protect ourselves from supply chain attacks by allowing a 3rd party to automatically merge code into the framework? As possibly annoying as it is, IMO every merge should be handled by a human.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants