chore(ci): run dependency review as one job on pull requests and merge groups

The merge_group pass-through added in #159 produced a second, skipped check
run with the same name on every pull request, because GitHub reports a check
for a job whose if: is false. The pinned dependency-review action resolves its
refs from merge_group.base_sha and head_sha itself, so the single real job now
triggers on both events with no conditions. Pull requests and merge groups
each get one check run, and the required check is still satisfied in the
queue.
This commit is contained in:
Adam Moussa 2026-09-18 19:15:24 -04:00
parent 10266e6e4b
commit 38588ac33e
No known key found for this signature in database

View file

@ -1,21 +1,12 @@
name: Dependency Review
on:
pull_request:
# The dependency-review action resolves the diff from merge_group.base_sha and
# head_sha itself, so the same job satisfies the required check in the merge
# queue. One job, no conditions, one check run per event.
merge_group:
permissions:
contents: read
jobs:
review:
if: github.event_name == 'pull_request'
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@4a6cbfd362140a68810f0f46d338026863b8e827 # v1.0.10
# The dependency-review action only diffs a pull request, and the org callable
# does not take explicit base and head refs. Every pull request in a merge
# group already passed the real review above before it could be queued, so the
# merge group reports the same required check name and passes.
review-merge-group:
if: github.event_name == 'merge_group'
name: review / dependency-review
runs-on: ubuntu-latest
steps:
- run: echo "Dependency review ran on the pull request before it entered the merge queue."