ci: add renovate auto-approve caller workflow - #748
Conversation
|
Warning Review limit reached
Next review available in: 49 minutes You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
What
renovate-auto-approve.yml(feat: add reusable renovate-auto-approve workflow dev-kit#25), pinned to8cb6197(post-v1.0.13 re-pin to the next release tag once cut, noted in the file)automergelabelWhy
The renovate-config presets set
automerge: true+ theautomergelabel on digest/patch/minor PRs, but Renovate cant approve its own PRs, so the required-review gate never clears. This workflow provides that approval for labeled PRs; anything labeledsecurityis skipped and an earlier approval revokedEverything else was already in place, verified via API: "Allow GitHub Actions to approve PRs" enabled,
protect-mainrequires 1 approval +check/lint/test/CodeQL,allow_auto_mergeon -> merges stay gated on CI, majors and security updates stay human-gated.Related: automerge policy (labels, update types, stability window) -> opendefensecloud/renovate-config#14, reusable workflow -> opendefensecloud/dev-kit#25.
Testing
CI config only, no runnable behavior change
YAML parses clean,
uses:ref resolves to the merged dev-kit workflow.Checklist