Skip to content

ci(claude-review): allow dependabot + renovate bots#11

Merged
topcoder1 merged 1 commit into
mainfrom
ci/allow-dependabot-bot
May 1, 2026
Merged

ci(claude-review): allow dependabot + renovate bots#11
topcoder1 merged 1 commit into
mainfrom
ci/allow-dependabot-bot

Conversation

@topcoder1
Copy link
Copy Markdown
Owner

Why

claude-code-action@v1 rejects bot-initiated PRs by default. When this reusable workflow is a required check, every dependabot PR is permanently blocked.

Hit on topcoder1/techrecon: 6 open dependabot PRs (#39-44) all blocked with:

```
Workflow initiated by non-human actor: dependabot (type: Bot).
Add bot to allowed_bots list or use '*' to allow all bots.
```

Fix

Whitelist dependabot + renovate explicitly. Avoid '*' so genuine random bot actors still get rejected.

Risk

Caller workflows that pin to `@main` pick this up automatically next run. Caller workflows pinned to a tag are unaffected until they upgrade.

claude-code-action@v1 rejects bot-initiated workflows by default with
"Workflow initiated by non-human actor: dependabot (type: Bot). Add bot
to allowed_bots list or use '*' to allow all bots."

When this reusable workflow is the required PR check on a project, every
dependabot PR is permanently blocked. We hit this with all 6 dependabot
PRs on topcoder1/techrecon (#39-44).

Whitelist dependabot + renovate explicitly. Avoid '*' so genuine random
bot actors still get rejected.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@topcoder1 topcoder1 enabled auto-merge (squash) May 1, 2026 02:20
@claude
Copy link
Copy Markdown

claude Bot commented May 1, 2026

No issues found. Change is minimal and correct — bot name format matches what the action reports, tool scope is already constrained via claude_args.

@topcoder1 topcoder1 merged commit 5548bc3 into main May 1, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant