Skip to content

Automatically update third party licenses during Dependabot PRs #11270

Description

@andyfeller

Overview

With cli/cli lint process erring if 3rd party license information is not updated in #11047, Dependabot PRs will require maintainers to manually run make licenses.

Recently, @williammartin opened #11269 with the script/fix-dependabot-licenses.sh script for maintainers to run that will find all Dependabot PRs and attempt to fix them where the lint workflow failed. This script is a manual repair effort, however it is possible to use a GitHub Actions workflow to run the make license script for Dependabot PRs:

name: Dependabot fetch metadata
on: pull_request

permissions:
  pull-requests: write
  issues: write

jobs:
  dependabot:
    runs-on: ubuntu-latest
    if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository == 'owner/my_repo'
    steps:
      - name: Dependabot metadata
        id: metadata
        uses: dependabot/fetch-metadata@d7267f607e9d3fb96fc2fbe83e0af444713e90b7
        with:
          github-token: "${{ secrets.GITHUB_TOKEN }}"
      # The following properties are now available:
      #  - steps.metadata.outputs.dependency-names
      #  - steps.metadata.outputs.dependency-type
      #  - steps.metadata.outputs.update-type

This issue is aimed at implementing GitHub Actions workflow changes that will automatically update third-party license source code and third-party-*.md reports, eliminating the need for maintainers to manually repair Dependabot PRs.

Note

To download the script/fix-dependabot-licenses.sh script, run the following command:

curl -o fix-dependabot-licenses.sh https://raw.githubusercontent.com/cli/cli/26d70bfb7bcc0b41dbdd50bfc51f827f1a5ad4c4/script/fix-dependabot-licenses.sh

Or checkout the original PR:

gh pr checkout https://github.com/cli/cli/pull/11269

Expected outcomes

  • When Dependabot PRs are opened, automation attempts to regenerate and commit updated license information via make licenses
  • When Dependabot PRs are updated, status checks pass without maintainer action outside of reviewing PR

Activity

  1. andyfeller commented on Jul 10, 2025

    @andyfeller
    ContributorAuthor

    One of the concerns raised that might prevent this from being automatically fixed is how GitHub Actions status checks are triggered by pushes using the secrets.GITHUB_TOKEN automatic token.

    This concern is related to Triggering a workflow from a workflow where GitHub Actions might not automatically re-run the status checks on the original PR for changes made by a different workflow:

    When you use the repository's GITHUB_TOKEN to perform tasks, events triggered by the GITHUB_TOKEN, with the exception of workflow_dispatch and repository_dispatch, will not create a new workflow run. This prevents you from accidentally creating recursive workflow runs. For example, if a workflow run pushes code using the repository's GITHUB_TOKEN, a new workflow will not run even when the repository contains a workflow configured to run when push events occur. For more information, see Use GITHUB_TOKEN in workflows.

    In the event we cannot automatically fix this as described, then we will reopen and merge @williammartin work in #11269 as to reduce maintainer toil.

  2. added
    enhancementa request to improve CLI
    coreThis issue is not accepting PRs from outside contributors
    github_actionsPull requests that update GitHub Actions code
    on Jul 15, 2025
  3. self-assigned this
    on Jul 17, 2025
  4. added
    discussFeature changes that require discussion primarily among the GitHub CLI team
    on Jul 17, 2025
  5. added a commit that references this issue on Jul 23, 2025
    99516d6
  6. self-assigned this
    on Jul 30, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

coreThis issue is not accepting PRs from outside contributorsdiscussFeature changes that require discussion primarily among the GitHub CLI teamenhancementa request to improve CLIgithub_actionsPull requests that update GitHub Actions code

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions