versionconductor

module
v0.4.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 2, 2026 License: MIT

README ΒΆ

VersionConductor

Go CI Go Lint Go SAST Docs Docs Visualization License

Automated dependency PR management and maintenance releases for GitHub repositories.

Part of the DevOpsOrchestra suite alongside PipelineConductor.

Features

  • πŸ” Scan - Find Renovate/Dependabot PRs across organizations
  • βœ… Review - Auto-approve dependency PRs based on Cedar policies
  • πŸ”€ Merge - Auto-merge approved PRs with configurable strategies
  • πŸš€ Release - Create maintenance releases when dependencies are updated
  • πŸ“Š Graph - Analyze dependency relationships across repositories
  • ⚑ GitHub Action - Automate everything with a reusable workflow

Installation

go install github.com/plexusone/versionconductor/cmd/versionconductor@latest

Quick Start

# Set token
export GITHUB_TOKEN=ghp_your_token

# Scan for dependency PRs
versionconductor scan --orgs myorg

# Review with 5-day quarantine policy
versionconductor review --orgs myorg --profile quarantine --execute

# Merge approved PRs
versionconductor merge --orgs myorg --execute

GitHub Action

Add automated dependency management to any repo:

# .github/workflows/go-dependency-automerge.yaml
name: Go Dependency Auto-Merge

on:
  schedule:
    - cron: "7,22,37,52 * * * *"  # Every 15 minutes
  workflow_dispatch:
    inputs:
      pr:
        description: 'PR number to evaluate'
        required: false
        type: string

permissions:
  contents: read
  pull-requests: write
  checks: read
  statuses: read

jobs:
  auto-merge:
    uses: plexusone/.github/.github/workflows/go-dependency-automerge.yaml@main
    with:
      profile: 'quarantine'
      min-age-days: 5
    secrets: inherit

See GitHub Action Setup for details.

Cedar Policies

VersionConductor uses Cedar for policy-driven automation.

The default Go dependency policy enforces:

Gate Description
Author Only dependabot[bot] or renovate[bot]
Files Only go.mod and go.sum changed
Directives No replace/exclude/toolchain changes
Version Patch or minor updates only (no major)
Age 5-day quarantine period
CI All checks must pass

Example Cedar policy:

@id("allow-patch-updates")
@action("AUTO_MERGE")
permit(
    principal,
    action == Action::"merge",
    resource
)
when {
    context.pr.author == "dependabot[bot]" &&
    context.pr.onlyGoModFiles == true &&
    context.goMod.hasDirectiveChanges == false &&
    context.dependency.isPatch == true &&
    context.pr.ageDays >= 5 &&
    context.ci.allPassed == true
};

The @action annotation specifies the decision outcome when the policy matches.

See Cedar Policies for full documentation.

Merge Profiles

Profile Min Age Patch Minor Major
aggressive 0 Auto Auto Auto
balanced 24h Auto Auto Manual
conservative 48h Auto Manual Manual
quarantine 5 days Auto Auto Manual
versionconductor review --orgs myorg --profile quarantine --execute

Commands

Command Description
scan List open dependency PRs
review Auto-approve PRs based on policy
merge Merge approved PRs
release Create maintenance releases
graph Dependency graph analysis
policy evaluate Evaluate policies against a PR

All write commands are dry-run by default. Use --execute to perform actions.

Policy Evaluation

Test policy evaluation locally or in CI:

# Evaluate a PR against policies
versionconductor policy evaluate --repo owner/repo --pr 123 --profile quarantine

# Post decision as PR comment
versionconductor policy evaluate --repo owner/repo --pr 123 --comment

Decisions include outcomes like AUTO_MERGE, QUEUE_FOR_MERGE, MANUAL_REVIEW, or SECURITY_TEAM_REVIEW.

Documentation

Full documentation available at plexusone.github.io/versionconductor

Development

# Clone
git clone https://github.com/plexusone/versionconductor
cd versionconductor

# Build
go build ./cmd/versionconductor

# Test
go test -v ./...

# Lint
golangci-lint run

License

MIT License - see LICENSE for details.

Directories ΒΆ

Path Synopsis
cmd
internal
observability
Package observability provides structured logging and optional telemetry integration for versionconductor using omniobserve.
Package observability provides structured logging and optional telemetry integration for versionconductor using omniobserve.
pkg

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL