Skip to content

ci: author, review, and automerge regen prs via github apps - #63

Merged
mekilis merged 4 commits into
mainfrom
ci/sdk-regen-auto-review
Jul 20, 2026
Merged

ci: author, review, and automerge regen prs via github apps#63
mekilis merged 4 commits into
mainfrom
ci/sdk-regen-auto-review

Conversation

@mekilis

@mekilis mekilis commented Jul 20, 2026

Copy link
Copy Markdown
Collaborator

Regen PRs are now authored with a convoy-sdk-bot GitHub App token (replacing the personal PAT), so CI triggers as before without depending on a user account. A separate reviewer app approves only diffs whose changed files all match the repo's generated paths; anything else is left unapproved with a comment for human review. Auto-merge is queued after approval, so unresolved finding conversations and the required checks (tests, Cursor Bugbot, Cursor Security Agent) still block the merge.


Note

Medium Risk
Automated approval and auto-merge on main are security-sensitive, but multiple explicit gates and a fail-open deny path limit blast radius to expected regen output only.

Overview
SDK generation now mints a convoy-sdk-bot GitHub App token for checkout, push, and PR creation instead of SDK_BOT_PAT / GITHUB_TOKEN, so pull_request CI still runs. Commits are attributed to convoy-sdk-bot[bot] rather than github-actions[bot].

When a regen diff exists, a second step mints an SDK reviewer app token and runs Approve and enable auto-merge. It only approves when the PR targets main, is authored by convoy-sdk-bot[bot], head matches the commit this run pushed, and changed files are exclusively client/client.gen.go (matching scripts/generate.sh). Any failed gate fails open to humans: comment, clear auto-merge if needed, no approval. After approval it re-checks head SHA to close a race, then enables squash auto-merge via the bot token so downstream publish workflows still fire.

Reviewed by Cursor Bugbot for commit fff78ef. Bugbot is set up for automated code reviews on this repo. Configure here.

Comment thread .github/workflows/sdk_generation.yaml Outdated
Comment thread .github/workflows/sdk_generation.yaml Outdated
Comment thread .github/workflows/sdk_generation.yaml Outdated
deny paths now clear stale auto-merge before commenting and fail the
step if the disable errors, instead of best-effort || true. an empty
changed-files listing no longer counts as an allowlist pass. renames
are checked on both sides everywhere. approvals are pinned to the
head commit.
Comment thread .github/workflows/sdk_generation.yaml
pin the approval to the head captured before the allowlist run, then
re-read the head after submitting; if it moved, dismiss the approval
and deny. dismiss_stale_reviews (now enabled) covers pushes after the
review; this covers the window before it.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 4977c5a. Configure here.

Comment thread .github/workflows/sdk_generation.yaml
a dismiss failure under set -e must not skip deny, which is the hard
gate that clears stale auto-merge. dismiss_stale_reviews already
covers the dismissal in the normal case.
@mekilis
mekilis merged commit 596b0fe into main Jul 20, 2026
5 checks passed
@mekilis
mekilis deleted the ci/sdk-regen-auto-review branch July 20, 2026 20:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant