Small GitHub App webhook service that approves selected pull requests so GitHub auto-merge can proceed when branch protection requires an approval.
The app approves a pull request only when all of these conditions are true:
- Every commit currently on the pull request has
commit.author.emailequal toci@js-soft.com. The email is configurable throughAPPROVED_AUTHOR_EMAIL. - The pull request only changes
package-lock.jsonand/or.nsprc. - The pull request has a
dependenciesorchorelabel. - The pull request adds at most 2 new top-level exception entries to
.nsprc. - GitHub's global security advisory for every added
.nsprcexception id has a severity oflow,medium, ormoderate.
Approvals are submitted without a review body. When the app does not approve a pull request, it requests review from the npm-dependency-update-reviewers GitHub team. It also adds a pull request comment explaining why, unless none of the pull request commits were authored by the configured approved author.
Create a GitHub App with:
- Webhook URL:
https://<your-host>/webhook - Webhook secret: any strong random value
- Subscribe to events:
Pull request - Repository permissions:
- Pull requests:
Read and write - Contents:
Read-only - Metadata:
Read-only, granted automatically by GitHub
- Pull requests:
Install the app on the repositories that should receive automatic approvals.
Set these environment variables:
GITHUB_APP_ID: GitHub App ID.GITHUB_PRIVATE_KEY: GitHub App private key PEM. Escaped\nnewlines are accepted.GITHUB_PRIVATE_KEY_PATH: Alternative toGITHUB_PRIVATE_KEY; path to a private key PEM file.GITHUB_WEBHOOK_SECRET: Webhook secret configured on the GitHub App.APPROVED_AUTHOR_EMAIL: Optional. Defaults toci@js-soft.com.PORT: Optional. Defaults to3000.
npm install
npm run build
npm startFor local development:
npm install
npm run devThe service exposes GET /healthz for health checks and POST /webhook for GitHub webhook delivery.
Git commit author emails and labels can be spoofed by users with sufficient repository access. Before broad production use, add checks for trusted repositories, branch names, check runs, signed commits, or the exact workflow/app actor that created the PR.