Something went wrong. Try again.
This repository has no description
Something went wrong. Try again.
README.md
Taze Update Action #
Automatically update dependencies using taze and create a pull request with the changes. This assumes that the project is using pnpm.
Features #
- Updates dependencies using taze
- Automatically runs
pnpm installafter updates - Creates a pull request with the changes
- Skips PR creation if no updates are available
Usage #
name: Update Dependencies
on:
schedule:
- cron: '0 0 * * 0' # Run weekly on Sunday at midnight
workflow_dispatch: # Allow manual trigger
jobs:
update-deps:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: pnpm/action-setup@v4
with:
version: 9
- uses: actions/setup-node@v4
with:
node-version: '24'
cache: 'pnpm'
- name: Update dependencies
uses: YOUR_USERNAME/taze-update-action@v1
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
Inputs #
| Input | Description | Required | Default |
|---|---|---|---|
taze-input |
Flags or args to pass to taze. We recommend low concurrency with GitHub runners | No | -w --concurrency 1 |
branch-prefix |
Prefix for the branch name | No | chore/update-deps |
pr-title |
Title for the pull request | No | chore: update dependencies |
pr-labels |
Comma-separated labels to add to the PR | No | dependencies |
github-token |
GitHub token for creating PRs | Yes | - |
Examples #
Update dependencies with custom options #
- uses: YOUR_USERNAME/taze-update-action@v1
with:
taze-input: '-w --concurrency 2'
branch-prefix: 'deps/update'
pr-title: 'Update dependencies'
pr-labels: 'dependencies,automated'
github-token: ${{ secrets.GITHUB_TOKEN }}
Update only minor versions #
- uses: YOUR_USERNAME/taze-update-action@v1
with:
taze-input: 'minor --concurrency 1'
github-token: ${{ secrets.GITHUB_TOKEN }}
Update only specific packages #
- uses: YOUR_USERNAME/taze-update-action@v1
with:
taze-input: '-w --include react,vue --concurrency 1'
github-token: ${{ secrets.GITHUB_TOKEN }}
Requirements #
-
Your project must use pnpm (I'd consider PRs to extend this somehow)
-
A Personal Access Token (PAT) with the following repository permissions:
- Read access to metadata
- Read and Write access to code, pull requests, and workflows
The PAT is required instead of
GITHUB_TOKENto trigger workflow runs on the created PR. Store it as a repository secret and use it in place ofsecrets.GITHUB_TOKEN.
How it works #
- Installs taze globally using pnpm
- Runs taze with the specified arguments to update dependencies
- Runs
pnpm install --no-frozen-lockfileto update the lockfile - Creates a new branch with the updates
- Commits the changes
- Pushes the branch to the repository
- Creates a pull request with the specified title and labels
If no dependency updates are available, the action exits gracefully without creating a PR.