The rubric, in force and unedited.
Every point below is awarded by code, from a source with a link. The model never adds, removes or reweights a factor. When the rubric changes it gets a new version number, and old scores keep the version they were computed under. Rubric v1.0.0, policy v1.0.0.
The action per band
Clear
Open a pull request with the bump and the brief. If Dependabot or Renovate already opened one for the same bump, comment there instead of duplicating it.
GRN-PR-1Caution
Open an issue carrying the brief and the migration steps the release notes asked for, labelled bumpwarden:review. No pull request.
AMB-ISSUE-1Held
Open a hold issue with a migration plan, labelled bumpwarden:hold. Never open a pull request for a held bump.
RED-HOLD-1Standing rules
bumpwarden never merges
Autonomy stops at the merge button by design. The agent opens, updates, labels and explains. A person presses merge. There is no configuration flag that changes this, because a flag that can be turned on is a promise that can be broken.
At most 10 actions in a run
Bumps are acted on riskiest first, and once 10 have landed the rest are carried to the next run rather than dropped. Each one that waits is recorded in the audit log saying so, so nothing goes quiet.
A first run over a long neglected repository would otherwise open dozens of issues at once, which is how a useful bot becomes one a maintainer blocks. The same run writes at most 20 briefs, and stops asking for them after 10 minutes so a slow answer upstream cannot push a run past its deadline. A bump that misses out is still scored and still acted on, and its page says which limit it met.
Briefs also go out at the model's pace, 2 at a time. The free tier answers 5 requests a minute and about 20 a day, and a brief costs two, so a long queue waits its turn rather than collecting refusals, and a bump the day has no room for keeps its score and gets its brief on a later run. A ready brief is kept, so a repeat run over the same bumps asks the model for nothing.
A pull request edits package.json only
When a clear bump earns a pull request, bumpwarden changes the version range in package.json and nothing else. The lockfile is not regenerated here, because bumpwarden does not run your package manager.
The pull request says so in its own body and asks you to run your installer on the branch before merging, so the lockfile is regenerated by the tool that owns it.
Every brief says a model wrote it
A brief is text an AI model generated, and it is posted into a repository without a person reading it first. So every issue, pull request and comment that carries one says so in plain words, names the model, and asks the reader to read the brief before acting on it. The same body carries a marker a machine can read.
Article 50 of the EU AI Act asks that machine-written text be recognisable as such, by the person reading it and by a machine, and that is where the shape of this came from. It is offered as a plain practice rather than as a claim to have met a legal test, which is not ours to declare. The score and the verdict are not the model's: they come from the rubric above.
A brief that speaks for bumpwarden is not published
Release notes are written by whoever publishes the package, and they reach the model inside the prompt. A model that follows an instruction planted there can write text that speaks in this agent's name, announces an approval, or tells you to merge without reading. None of that can move the score, which is arithmetic over the rubric above. It could still sit in an issue signed by this agent and be believed.
So a brief carrying any of the three is dropped rather than labelled. The bump keeps its score and its verdict, and the issue says the brief did not pass, in the same words it uses when the model returns nothing at all. What is checked is the model's own prose, never a quotation it took from the release notes, because judging those would let one word in a changelog silence every brief written about it.