This is an automated email from the ASF dual-hosted git repository. ppkarwasz pushed a commit to branch feat/main/analyze-dependabot in repository https://gitbox.apache.org/repos/asf/logging-log4j2.git
commit 7b2090ce97dcf26cca7ad3a1289ed516836c1830 Author: Piotr P. Karwasz <[email protected]> AuthorDate: Thu Sep 3 12:25:20 2026 +0200 Add `Dependabot Analyze PR` workflow to `main` The `pull_request` trigger runs the workflow file from the PR merge commit, so `main` needs its own copy for Dependabot PRs against it. The follow-up `Dependabot Process PR` workflow is triggered by `workflow_run`, which GitHub only evaluates on the default branch, so the copy on `2.x` handles PRs against every branch and selects the changelog directory based on the base branch of the PR. Assisted-By: Claude Fable 5.1 <[email protected]> Claude-Session: https://claude.ai/code/session_014QXFCr2hQv3zoVf7wo5Lab --- .github/workflows/analyze-dependabot.yaml | 41 +++++++++++++++++++++++++++++++ 1 file changed, 41 insertions(+) diff --git a/.github/workflows/analyze-dependabot.yaml b/.github/workflows/analyze-dependabot.yaml new file mode 100644 index 0000000000..8fefb38935 --- /dev/null +++ b/.github/workflows/analyze-dependabot.yaml @@ -0,0 +1,41 @@ +# +# Licensed to the Apache Software Foundation (ASF) under one or more +# contributor license agreements. See the NOTICE file distributed with +# this work for additional information regarding copyright ownership. +# The ASF licenses this file to you under the Apache License, Version 2.0 +# (the "License"); you may not use this file except in compliance with +# the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +name: "Dependabot Analyze PR" + +on: + # `pull_request` runs the workflow file from the PR merge commit, so this copy applies to PRs against `main`. + # The follow-up "Dependabot Process PR" workflow is triggered by `workflow_run`, which GitHub only evaluates + # on the default branch (`2.x`), so it does not need a copy here. The copy on `2.x` selects the changelog + # directory based on the base branch of the PR. + pull_request: + +# Default permissions for each job. +# Additional permissions should be assigned on a per-job basis. +permissions: { } + +jobs: + + analyze-dependabot: + # `github.actor` prevents recursive calls when `github-actions[bot]` pushes to the PR; + # `github.event.pull_request.user.login` skips PRs not opened by Dependabot. + if: ${{ + github.repository == 'apache/logging-log4j2' + && github.actor == 'dependabot[bot]' + && github.event.pull_request.user.login == 'dependabot[bot]' + }} + uses: apache/logging-parent/.github/workflows/analyze-dependabot-reusable.yaml@gha/v0
