ENGINEERING
Auto-merge low-risk bumps and block high-risk ones
Acts as a gatekeeper on dependency-bump PRs: if the transitive blast-radius score is below threshold and no new CVEs appear, it approves and auto-merges; if it's high, it blocks…
How it runs
The automated pipeline, trigger to output.
- TriggerDependency-bump PR openedGitHub
- ActionResolve transitive set and fetch advisoriesGitHub
- LogicScore and decide auto-merge vs block
- ActionApprove and enable auto-merge (low risk)GitHub
- OutputPost blocking review with reasons (high risk)GitHub
What it does
Closes the loop between scoring and action. Low-risk bumps with no new transitive CVEs get approved and merged automatically, clearing the queue. High-risk bumps get blocked with a required-review request and a comment explaining exactly which packages and advisories triggered the block.
When to use it
Use it when you trust your scoring and want to stop hand-merging dozens of safe patch bumps while guaranteeing risky ones never auto-merge. It pairs naturally with the escalation safety net.
How it works
- 1A GitHub pull_request event fires on a bump PR.
- 2The flow resolves the transitive set and fetches advisories for affected packages.
- 3A logic branch evaluates the blast-radius score and whether any new CVE was introduced.
- 4On the low-risk path it approves the PR and enables auto-merge via the GitHub API.
- 5On the high-risk path it posts a blocking review requesting changes, listing the offending packages and advisory IDs.
- 6Either way it leaves a check run recording the decision.
Set it up
What you configure once, before turning it on.
- 1Connect GitHubRepos, issues, pull requests, actions.
- 2Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
- 3Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
- 4Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.
More Engineering workflows
Gate breaking API PRs behind downstream consumer acknowledgement
When a PR introduces a breaking contract change, comments the impact summary back on the PR, applies a blocking label.
Publish a versioned API changelog to Confluence on each release tag
On a new semver release tag, gathers the contract changes since the last release and writes a clean.
Agent reviews model-license fit and suggests compliant swaps on the PR
When a PR adds a Hugging Face model, an agent reads the model card and license, judges fit against your commercial-use policy.
Upgrade Impact Router to Module Code Owners
Maps a dependency-bump PR's affected modules to their CODEOWNERS, then DMs each owner on Slack with only the changelog slice that touches code they own.
Re-Voice IVR Prompts on Phone-Tree Config Merge
When a phone-tree config change merges in GitHub, regenerates the ElevenLabs audio for any prompt whose script changed in the diff and opens a follow-up PR adding the new audio…
Upstream Release to Notion Upgrade Brief
When a watched package publishes a new release, fetches the release notes, maps them to the internal modules that depend on it.
Run it inside a business
This workflow drops into a full company template. Import the org, and this is one of the playbooks its agents run.

Run this workflow in your colony.
14-day trial. No DevOps. No Sales call. Provisioned in under a minute.
