Skip to content

Add centralized /dependabot-burner grouping and retry-aware single-workflow remediation - #40396

Merged
pelikhan merged 6 commits into
mainfrom
copilot/update-dependabot-burner-support
Jun 20, 2026
Merged

Add centralized /dependabot-burner grouping and retry-aware single-workflow remediation#40396
pelikhan merged 6 commits into
mainfrom
copilot/update-dependabot-burner-support

Conversation

CopilotAI commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

This updates dependabot-burner to support direct PR invocation via a centralized /dependabot-burner command and to drive a single grouped remediation attempt inside the burner workflow itself. It also teaches the burner to reuse signal from prior failed burner PRs and maintainer-only feedback when deciding the next retry shape. The old dependabot-campaign and dependabot-worker workflows have been removed — dependabot-burner is now the single workflow handling all Dependabot remediation.

  • Centralized PR entrypoint

    • Adds a centralized slash_command trigger for /dependabot-burner on PR comments and review comments.
    • Prefetches Dependabot PR context so slash-command runs can start from the triggering PR instead of scanning the full backlog blindly.
  • Filtered related-PR grouping

    • Builds a grouped batch from PRs that touch the same generated manifest targets as the triggering PR.
    • Posts a single status comment on slash-command runs when related PRs are grouped, so maintainers can quickly review the intended batch and spot unrelated items.
  • Retry-aware burner orchestration

    • Scans recent closed unmerged [dependabot-burner] PRs and passes that history into the next attempt.
    • Falls back cleanly when Dependabot PR titles do not match the strict bump-title pattern by preserving raw title context instead of dropping dependency identity.
  • Maintainer-only feedback loop

    • Explicitly scopes retry guidance to maintainer/admin/write feedback and ignores non-maintainer noise.
    • Distinguishes first-attempt vs retry flows so the burner can adapt behavior without widening scope.
  • Single-workflow remediation strategy

    • Moves the remediation path into dependabot-burner so the burner owns source edits, validation, and replacement-PR creation in one workflow.
    • Removes dependabot-campaign and dependabot-worker; their responsibilities are fully absorbed by dependabot-burner via inline subagents.
  • Subagent-based PR analysis and execution

    • Adds burner-side subagents for PR-group validation, retry-history analysis, dependency-batch mapping, retry-feedback synthesis, and the single bounded remediation wave.
on:
slash_command:
strategy: centralizedname: dependabot-burnerevents: [pull_request_comment, pull_request_review_comment]safe-outputs:
create-pull-request:
title-prefix: "[dependabot-burner] "max: 1

CopilotAIand others added 2 commits June 19, 2026 21:59
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
CopilotAI changed the title Update dependabot-burner slash-command grouping flowAdd centralized /dependabot-burner grouping and retry-aware single-PR remediationJun 19, 2026
CopilotAI requested a review from pelikhanJune 19, 2026 22:06
@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot merge dependabot worker into the dependabot burner as a sub agent. Single AW.

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

CopilotAI commented Jun 19, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot merge dependabot worker into the dependabot burner as a sub agent. Single AW.

Addressed in fe94006. dependabot-burner now performs the remediation through inline subagents in the same workflow, and the compiled lock no longer dispatches to dependabot-worker.

CopilotAI changed the title Add centralized /dependabot-burner grouping and retry-aware single-PR remediationAdd centralized /dependabot-burner grouping and retry-aware single-workflow remediationJun 19, 2026
@pelikhan
pelikhan marked this pull request as ready for review June 20, 2026 01:04
CopilotAI review requested due to automatic review settings June 20, 2026 01:04
@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot remove the old agentic-workflows that handled dependent-bot tasks and keep only the new dependent-bot burner.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR evolves the Dependabot automation workflows to support a centralized /dependabot-burner slash-command entrypoint and to run a single grouped remediation wave within the burner workflow, incorporating retry history and maintainer-only feedback into subsequent attempts.

Changes:

  • Adds a /dependabot-burner centralized slash-command trigger and prefetches PR context to build a related-PR batch.
  • Introduces retry-aware inputs (retry context + maintainer feedback) and threads them through the existing worker/campaign dispatch plumbing.
  • Updates the burner workflow’s compiled lock manifest to support comment/PR safe-outputs, CLI proxy usage, and the new orchestration flow.
Show a summary per file
FileDescription
.github/workflows/dependabot-worker.mdAdds retry/maintainer-feedback inputs and updates worker instructions/output fields for retry-aware execution.
.github/workflows/dependabot-worker.lock.ymlRegenerates the compiled workflow to include new inputs and updated safe-outputs title prefix.
.github/workflows/dependabot-campaign.lock.ymlThreads new retry/feedback inputs through the campaign → worker invocation payload in the compiled workflow.
.github/workflows/dependabot-burner.mdReplaces the burner definition with a centralized slash-command + grouped remediation orchestrator and subagents.
.github/workflows/dependabot-burner.lock.ymlRegenerates the compiled burner workflow with pre-activation role checks, safe-outputs, CLI proxy, and updated permissions.
.github/workflows/agentic_commands.ymlRegisters /dependabot-burner routing to the new workflow.

Copilot's findings

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 6/6 changed files
  • Comments generated: 2

Comment on lines +183 to +203
async function listRecentClosedBurnerPRs() {
const pulls = await github.paginate(github.rest.pulls.list, {
owner: context.repo.owner,
repo: context.repo.repo,
state: 'closed',
per_page: 100,
});

return pulls
.filter((pull) => pull.title?.startsWith('[dependabot-burner] ') && !pull.merged_at)
.slice(0, 20)
.map((pull) => ({
number: pull.number,
title: pull.title,
body: pull.body || '',
url: pull.html_url,
closed_at: pull.closed_at,
created_at: pull.created_at,
}))
.sort((a, b) => new Date(b.closed_at || b.created_at).getTime() - new Date(a.closed_at || a.created_at).getTime());
}
Comment on lines +134 to +142
async function loadPullFiles(pullNumber) {
const files = await github.paginate(github.rest.pulls.listFiles, {
owner: context.repo.owner,
repo: context.repo.repo,
pull_number: pullNumber,
per_page: 100,
});
return files.map((file) => file.filename).filter((filename) => manifestTargets.has(filename));
}
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

CopilotAI commented Jun 20, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot remove the old agentic-workflows that handled dependent-bot tasks and keep only the new dependent-bot burner.

Done in the latest commit. Removed dependabot-campaign.md, dependabot-campaign.lock.yml, dependabot-worker.md, and dependabot-worker.lock.yml. dependabot-burner is now the single workflow handling all Dependabot remediation.

@github-actionsgithub-actionsBot mentioned this pull request Jun 20, 2026
@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot merge main

CopilotAIand others added 2 commits June 20, 2026 02:36
…abot-burner-support
# Conflicts:
#	.github/workflows/agentic_commands.yml
#	.github/workflows/dependabot-burner.lock.yml
#	.github/workflows/dependabot-campaign.lock.yml
#	.github/workflows/dependabot-campaign.md
#	.github/workflows/dependabot-worker.lock.yml
#	.github/workflows/dependabot-worker.md
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

CopilotAI commented Jun 20, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot merge main

Done — merged origin/main and recompiled all workflows.

CopilotAI requested a review from pelikhanJune 20, 2026 02:42
@pelikhan
pelikhan merged commit 9ad5040 into mainJun 20, 2026
@pelikhan
pelikhan deleted the copilot/update-dependabot-burner-support branch June 20, 2026 02:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@pelikhan