This is an automated email from the ASF dual-hosted git repository. ppkarwasz pushed a commit to branch 2.26.x in repository https://gitbox.apache.org/repos/asf/logging-log4j2.git
commit 913534f51c7f3a329a6919ac94b0a191d6d673ed Author: Piotr P. Karwasz <[email protected]> AuthorDate: Wed Sep 2 22:23:28 2026 +0200 Add Dependabot `analyze` and `process` workflows Copies `analyze-dependabot.yaml` and `process-dependabot.yaml` from `2.x`. Co-Authored-By: Claude Fable 5.1 <[email protected]> Claude-Session: https://claude.ai/code/session_01R7BoincUoL8YtZsf3xjvuf --- .github/workflows/analyze-dependabot.yaml | 37 ++++++++++++++++++++++++ .github/workflows/process-dependabot.yaml | 48 +++++++++++++++++++++++++++++++ 2 files changed, 85 insertions(+) diff --git a/.github/workflows/analyze-dependabot.yaml b/.github/workflows/analyze-dependabot.yaml new file mode 100644 index 0000000000..cd991d3637 --- /dev/null +++ b/.github/workflows/analyze-dependabot.yaml @@ -0,0 +1,37 @@ +# +# Licensed to the Apache Software Foundation (ASF) under one or more +# contributor license agreements. See the NOTICE file distributed with +# this work for additional information regarding copyright ownership. +# The ASF licenses this file to you under the Apache License, Version 2.0 +# (the "License"); you may not use this file except in compliance with +# the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +name: "Dependabot Analyze PR" + +on: + pull_request: + +# Default permissions for each job. +# Additional permissions should be assigned on a per-job basis. +permissions: { } + +jobs: + + analyze-dependabot: + # `github.actor` prevents recursive calls when `github-actions[bot]` pushes to the PR; + # `github.event.pull_request.user.login` skips PRs not opened by Dependabot. + if: ${{ + github.repository == 'apache/logging-log4j2' + && github.actor == 'dependabot[bot]' + && github.event.pull_request.user.login == 'dependabot[bot]' + }} + uses: apache/logging-parent/.github/workflows/analyze-dependabot-reusable.yaml@gha/v0 diff --git a/.github/workflows/process-dependabot.yaml b/.github/workflows/process-dependabot.yaml new file mode 100644 index 0000000000..d67dfbdebd --- /dev/null +++ b/.github/workflows/process-dependabot.yaml @@ -0,0 +1,48 @@ +# +# Licensed to the Apache Software Foundation (ASF) under one or more +# contributor license agreements. See the NOTICE file distributed with +# this work for additional information regarding copyright ownership. +# The ASF licenses this file to you under the Apache License, Version 2.0 +# (the "License"); you may not use this file except in compliance with +# the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +name: "Dependabot Process PR" + +on: + workflow_run: + workflows: + - "Dependabot Analyze PR" + types: + - completed + +# Default permissions for each job. +# Additional permissions should be assigned on a per-job basis. +permissions: { } + +jobs: + + process-dependabot: + # Skip this workflow on commits not pushed by Dependabot + if: ${{ + github.repository == 'apache/logging-log4j2' + && github.actor == 'dependabot[bot]' + && github.event.workflow_run.conclusion == 'success' + }} + uses: apache/logging-parent/.github/workflows/process-dependabot-reusable.yaml@gha/v0 + permissions: + # Append the changelog commit + contents: write + # Convert the PR into draft + pull-requests: write + with: + # The path to the changelog directory for the current development branch. + changelog-path: src/changelog/.2.x.x
