Skip to content

release: v0.8.2 (ruleset bypass extras, pull-request-only admins, the graphify guide) - #76

Merged
brunogbv merged 4 commits into
mainfrom
chore/release-v0.8.2
Oct 10, 2026
Merged

brunogbv merged 4 commits into
mainfrom
chore/release-v0.8.2

Conversation

@brunogbv

Copy link
Copy Markdown
Collaborator

Summary — The umbrella's main-rule keeps the marola-pointer-sync App only if ruleset-sync knows about per-repo extras, and the shared manifest's admins move to pull_request; both reach the repos only through a tag and a just rulesets-apply per repo after it. No workflow in the consumers or the devkit pushes to a default branch, so the apply stops only a person's direct push to main.

MIP none — not MIP-scoped
Tested ⬜ gates · ⬜ e2e · ⬜ live · ⬜ ci-only — release.py --check 0.8.2 actionlint docs_lint tests/self-tests.sh —
Cost ~$7.53 · diff-size estimate (cost-split --estimate-commit) (719b1bd)

What changed

  • release: v0.8.2 (ruleset bypass extras, admins PR-only on main) (719b1bd)

Stacked on #74. Merge #74 first; this then retargets to main. release.py --check 0.8.2, actionlint, docs-lint and the self-tests pass.

After merge and tag: bump-consumers opens six v0.8.2 bump PRs. Then, per repo, not --all-org (that would also create rulesets on awesome-ocean-science/agent-skills and rewrite .github's): just rulesets-apply marola-dev/<repo> for each of the seven. Cascade check (all seven repos' workflows and scripts): nothing pushes to a default branch — automation pushes only to chore/*, site-data, api-docs, PR heads and tags — so only a person's direct git push origin main stops working; PR merges with the admin bypass keep working.

brunogbv and others added 4 commits October 10, 2026 03:53
…a's App

marola-dev/marola's main-rule now differs from the shared manifest on
purpose: the marola-pointer-sync App (Integration 5257042) can bypass
through a PR to merge pointer-sync's PR (marola-dev/marola#739), and both
admin bypasses are pull_request instead of always, so no admin PAT can
push straight to main. check reported that as drift, and apply would
have silently dropped the App (auto-merge stops, no error) and reopened
direct pushes to main.

.github/rulesets/bypass-extras.json, keyed by owner/repo, holds each
repo's exceptions with a required one-line reason. check and apply merge
them into the manifest's bypass list by (actor_type, actor_id): a match
overrides bypass_mode, anything else is added, and the reason is stripped
since GitHub doesn't store it. A live actor in neither the base nor the
extras is still drift, and so is a missing extra. A repo without extras
is compared against, and sent, the manifest byte for byte, as before.
Bypass actors now sort by (actor_type, actor_id) so two actors of one
type can't drift on order alone.

The base manifest's admin modes stay at always for every repo: moving
them to pull_request org-wide is the maintainer's open decision (#68,
point 2). Until then the umbrella's admin modes are extras too.

Closes #68

Tested: ruleset-sync --self-test red (30 failures, before the change) then green (ok, incl. check_ok_with_repo_extras, check_drifted_when_extra_missing, check_drifted_on_unlisted_actor, apply_keeps_extras, extras_entry_needs_reason); shellcheck clean (error and default severity); docs-lint clean; tests/self-tests.sh all ok; real read-only check: marola-dev/marola ok (drifted before), marola-dev/marola-app ok
Cost: ~$9.23 · diff-size estimate (cost-split --estimate-commit)
Co-Authored-By: Claude <noreply@anthropic.com>
The maintainer decided #68's point 2 (2026-10-10): the shared manifest
moves both admin bypass actors (OrganizationAdmin, RepositoryRole 5) from
always to pull_request, so no admin, and no admin's PAT, can push
straight to any repo's main. The umbrella's two admin overrides in
bypass-extras.json are now the base and go; its one remaining extra is
the marola-pointer-sync App (marola-dev/marola#739).

The self-test's fixture stays synthetic, still overriding a base actor's
mode and adding one the base lacks; only its reasons now say so.

Until `just rulesets-apply` runs per repo after the release, check
reports every repo but the umbrella as drifted on exactly those two
modes.

Part of #68

Tested: ruleset-sync --self-test ok; shellcheck clean; docs-lint clean; tests/self-tests.sh all ok; real read-only check: marola-dev/marola ok; --all-org marola-dev check: marola ok, devkit/site/corpus/ml/app/oods/.github drifted on the two admin bypass_mode lines only, awesome-ocean-science and agent-skills missing (no main-rule, as before)
Cost: ~$3.08 · diff-size estimate (cost-split --estimate-commit)
Co-Authored-By: Claude <noreply@anthropic.com>
The umbrella's main-rule keeps the marola-pointer-sync App only if
ruleset-sync knows about per-repo extras, and the shared manifest's
admins move to pull_request; both reach the repos only through a tag
and a `just rulesets-apply` per repo after it. No workflow in the
consumers or the devkit pushes to a default branch, so the apply stops
only a person's direct push to main.

Tested: release.py --check 0.8.2; actionlint; docs_lint; tests/self-tests.sh
Cost: ~$7.53 · diff-size estimate (cost-split --estimate-commit)
Co-Authored-By: Claude <noreply@anthropic.com>
Tested: release.py --check 0.8.2, ruleset-sync --self-test and docs_lint on the merged tree
Cost: n/a (restack merge)
Co-Authored-By: Claude <noreply@anthropic.com>
@brunogbv
brunogbv changed the base branch from fix/ruleset-sync-repo-extras to main October 10, 2026 02:13
@brunogbv
brunogbv merged commit 2bfee3b into main Oct 10, 2026
16 of 20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant