Exempt Dependabot PRs from the PR gate (#4395)

## What

Adds a trusted-bot exception to the PR gate so Dependabot's PRs are no
longer auto-closed.

## Why

The PR gate (`scripts/pr-gate/`, run by `.github/workflows/pr-gate.yml`)
auto-closes PRs that don't fit the contribution workflow. Dependabot PRs
were getting closed because the bot:

- has no repo permission,
- links no `approved` issue, and
- opens dependency bumps that often exceed the 50-line small-fix cap.

## How

- `config.ts` — new `TRUSTED_BOT_AUTHORS` constant (currently
`["dependabot[bot]"]`), so the allowlist is easy to extend.
- `rules.ts` — new `checkTrustedBot()` rule, wired into `evaluate()`
right after the maintainer bypass and before the repo-access check.
- `tests/PrGateRules.test.ts` — unit tests for the rule plus an
`evaluate()`-level test proving a 5000-line Dependabot PR now passes
instead of closing.
- `README.md` — documented the new rule in the gate-logic ordering.

The match is exact, so a lookalike login (e.g. `not-dependabot[bot]`)
won't slip through. Add more bots (Renovate, etc.) to
`TRUSTED_BOT_AUTHORS` as needed.

## Testing

`npx vitest tests/PrGateRules.test.ts --run` → 39 passed. Lint +
prettier clean.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Evan
2026-06-23 15:45:26 -07:00
committed by GitHub
co-authored by Claude Opus 4.8
parent 1cb84a79df
commit c63bfb6d94
4 changed files with 53 additions and 4 deletions
+5 -4
View File
@@ -5,10 +5,11 @@ Deterministic GitHub Action that auto-closes PRs that don't follow the project's
## Gate logic (first match wins)
1. **Maintainer bypass** — PR carries the `bypass-pr-check` label → pass. Apply this label and reopen if the gate closed something you wanted through.
2. **Org/repo member bypass**`author_association` is `OWNER`, `MEMBER`, or `COLLABORATOR` → pass.
3. **Approved-work bypass** — PR body links an issue (via `Closes #N` / `Fixes #N` / `Resolves #N`) that carries the `approved` label, and the PR author is in the issue's assignees → pass.
4. **Small-fix bypass**`additions + deletions ≤ 50` → pass + apply `small-fix` label.
5. **Otherwise** — apply `auto-closed-needs-issue` label, post rejection comment, close.
2. **Trusted-bot bypass**PR author is a trusted bot (e.g. `dependabot[bot]`) → pass. List is in `TRUSTED_BOT_AUTHORS`.
3. **Org/repo member bypass**`author_association` is `OWNER`, `MEMBER`, or `COLLABORATOR` → pass.
4. **Approved-work bypass**PR body links an issue (via `Closes #N` / `Fixes #N` / `Resolves #N`) that carries the `approved` label, and the PR author is in the issue's assignees → pass.
5. **Small-fix bypass**`additions + deletions ≤ 50` → pass + apply `small-fix` label.
6. **Otherwise** — apply `auto-closed-needs-issue` label, post rejection comment, close.
## Local testing